VMRay Analyzer Report
Kernel Graph 1
No Kernel Graph Available
Code Block #1 ( EP #1)
+
InformationValue
Triggerusbehub.sys
Start Address0xfffff88003908d40
Execution Path #1 (length: 211, amount: 1, processes: 1)
+
InformationValue
Sequence Length211
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
RtlInitUnicodeStringSourceString = \Device\VBoxDrv, DestinationString_out = \Device\VBoxDrv
IoCreateDeviceDriverObject_unk = 0xfffffa8002fcb5d0, DeviceExtensionSize = 0x1108, DeviceName = \Device\VBoxDrv, DeviceType_unk = 0x22, DeviceCharacteristics = 0x0, Exclusive = 0, DeviceObject_unk_out = 0xfffff88004789870, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = \DosDevices\VBoxDrv, DestinationString_out = \DosDevices\VBoxDrv
IoCreateSymbolicLinkSymbolicLinkName = \DosDevices\VBoxDrv, DeviceName = \Device\VBoxDrv, ret_val_unk_out = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x20, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8001f5a870
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x50, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8003126570
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80031265a0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x50, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8003074780
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80030747b0
KeQueryActiveProcessorsret_val_unk_out = 0x1
MmAllocateContiguousMemoryNumberOfBytes_ptr = 0x1000, HighestAcceptableAddress_unk = 0xffffffff, ret_val_ptr_out = 0xfffffa8001927000
IoAllocateMdlVirtualAddress_ptr = 0xfffffa8001927000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00
MmBuildMdlForNonPagedPoolMemoryDescriptorList_unk = 0xfffffa8003209a00, MemoryDescriptorList_unk_out = 0xfffffa8003209a00
ExSetTimerResolutionDesiredTime = 0x2625a, SetResolution = 1, ret_val_out = 0x26161
ExSetTimerResolutionDesiredTime = 0x0, SetResolution = 0, ret_val_out = 0x26161
KeQueryActiveProcessorsret_val_unk_out = 0x1
MmGetPhysicalAddressBaseAddress_ptr = 0xfffffa8001927000, ret_val_unk_out = 0x7fe21000
KeInitializeTimerExType_unk = 0x1, Timer_unk_out = 0xfffffa8003167210
KeInitializeDpcDeferredRoutine_unk = 0xfffff880039085b0, DeferredContext_ptr = 0xfffffa80031671a0, Dpc_unk_out = 0xfffffa8003167250
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167290
KeSetImportanceDpcDpc_unk = 0xfffffa8003167290, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167290
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167290, Number = 0, Dpc_unk_out = 0xfffffa8003167290
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031672d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031672d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031672d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031672d0, Number = 1, Dpc_unk_out = 0xfffffa80031672d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167310
KeSetImportanceDpcDpc_unk = 0xfffffa8003167310, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167310
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167310, Number = 2, Dpc_unk_out = 0xfffffa8003167310
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167350
KeSetImportanceDpcDpc_unk = 0xfffffa8003167350, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167350
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167350, Number = 3, Dpc_unk_out = 0xfffffa8003167350
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167390
KeSetImportanceDpcDpc_unk = 0xfffffa8003167390, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167390
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167390, Number = 4, Dpc_unk_out = 0xfffffa8003167390
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031673d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031673d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031673d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031673d0, Number = 5, Dpc_unk_out = 0xfffffa80031673d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167410
KeSetImportanceDpcDpc_unk = 0xfffffa8003167410, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167410
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167410, Number = 6, Dpc_unk_out = 0xfffffa8003167410
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167450
KeSetImportanceDpcDpc_unk = 0xfffffa8003167450, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167450
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167450, Number = 7, Dpc_unk_out = 0xfffffa8003167450
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167490
KeSetImportanceDpcDpc_unk = 0xfffffa8003167490, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167490
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167490, Number = 8, Dpc_unk_out = 0xfffffa8003167490
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031674d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031674d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031674d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031674d0, Number = 9, Dpc_unk_out = 0xfffffa80031674d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167510
KeSetImportanceDpcDpc_unk = 0xfffffa8003167510, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167510
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167510, Number = 10, Dpc_unk_out = 0xfffffa8003167510
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167550
KeSetImportanceDpcDpc_unk = 0xfffffa8003167550, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167550
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167550, Number = 11, Dpc_unk_out = 0xfffffa8003167550
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167590
KeSetImportanceDpcDpc_unk = 0xfffffa8003167590, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167590
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167590, Number = 12, Dpc_unk_out = 0xfffffa8003167590
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031675d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031675d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031675d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031675d0, Number = 13, Dpc_unk_out = 0xfffffa80031675d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167610
KeSetImportanceDpcDpc_unk = 0xfffffa8003167610, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167610
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167610, Number = 14, Dpc_unk_out = 0xfffffa8003167610
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167650
KeSetImportanceDpcDpc_unk = 0xfffffa8003167650, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167650
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167650, Number = 15, Dpc_unk_out = 0xfffffa8003167650
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167690
KeSetImportanceDpcDpc_unk = 0xfffffa8003167690, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167690
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167690, Number = 16, Dpc_unk_out = 0xfffffa8003167690
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031676d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031676d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031676d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031676d0, Number = 17, Dpc_unk_out = 0xfffffa80031676d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167710
KeSetImportanceDpcDpc_unk = 0xfffffa8003167710, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167710
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167710, Number = 18, Dpc_unk_out = 0xfffffa8003167710
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167750
KeSetImportanceDpcDpc_unk = 0xfffffa8003167750, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167750
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167750, Number = 19, Dpc_unk_out = 0xfffffa8003167750
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167790
KeSetImportanceDpcDpc_unk = 0xfffffa8003167790, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167790
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167790, Number = 20, Dpc_unk_out = 0xfffffa8003167790
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031677d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031677d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031677d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031677d0, Number = 21, Dpc_unk_out = 0xfffffa80031677d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167810
KeSetImportanceDpcDpc_unk = 0xfffffa8003167810, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167810
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167810, Number = 22, Dpc_unk_out = 0xfffffa8003167810
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167850
KeSetImportanceDpcDpc_unk = 0xfffffa8003167850, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167850
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167850, Number = 23, Dpc_unk_out = 0xfffffa8003167850
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167890
KeSetImportanceDpcDpc_unk = 0xfffffa8003167890, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167890
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167890, Number = 24, Dpc_unk_out = 0xfffffa8003167890
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031678d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031678d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031678d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031678d0, Number = 25, Dpc_unk_out = 0xfffffa80031678d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167910
KeSetImportanceDpcDpc_unk = 0xfffffa8003167910, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167910
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167910, Number = 26, Dpc_unk_out = 0xfffffa8003167910
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167950
KeSetImportanceDpcDpc_unk = 0xfffffa8003167950, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167950
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167950, Number = 27, Dpc_unk_out = 0xfffffa8003167950
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167990
KeSetImportanceDpcDpc_unk = 0xfffffa8003167990, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167990
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167990, Number = 28, Dpc_unk_out = 0xfffffa8003167990
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031679d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031679d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031679d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031679d0, Number = 29, Dpc_unk_out = 0xfffffa80031679d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167a10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167a10, Number = 30, Dpc_unk_out = 0xfffffa8003167a10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167a50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167a50, Number = 31, Dpc_unk_out = 0xfffffa8003167a50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167a90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167a90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167a90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167a90, Number = 32, Dpc_unk_out = 0xfffffa8003167a90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167ad0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167ad0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167ad0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167ad0, Number = 33, Dpc_unk_out = 0xfffffa8003167ad0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167b10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167b10, Number = 34, Dpc_unk_out = 0xfffffa8003167b10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167b50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167b50, Number = 35, Dpc_unk_out = 0xfffffa8003167b50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167b90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167b90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167b90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167b90, Number = 36, Dpc_unk_out = 0xfffffa8003167b90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167bd0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167bd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167bd0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167bd0, Number = 37, Dpc_unk_out = 0xfffffa8003167bd0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167c10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167c10, Number = 38, Dpc_unk_out = 0xfffffa8003167c10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167c50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167c50, Number = 39, Dpc_unk_out = 0xfffffa8003167c50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167c90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167c90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167c90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167c90, Number = 40, Dpc_unk_out = 0xfffffa8003167c90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167cd0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167cd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167cd0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167cd0, Number = 41, Dpc_unk_out = 0xfffffa8003167cd0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167d10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167d10, Number = 42, Dpc_unk_out = 0xfffffa8003167d10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167d50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167d50, Number = 43, Dpc_unk_out = 0xfffffa8003167d50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167d90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167d90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167d90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167d90, Number = 44, Dpc_unk_out = 0xfffffa8003167d90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167dd0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167dd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167dd0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167dd0, Number = 45, Dpc_unk_out = 0xfffffa8003167dd0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167e10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167e10, Number = 46, Dpc_unk_out = 0xfffffa8003167e10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167e50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167e50, Number = 47, Dpc_unk_out = 0xfffffa8003167e50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167e90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167e90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167e90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167e90, Number = 48, Dpc_unk_out = 0xfffffa8003167e90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167ed0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167ed0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167ed0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167ed0, Number = 49, Dpc_unk_out = 0xfffffa8003167ed0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f10
KeSetImportanceDpcDpc_unk = 0xfffffa8003167f10, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f10
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167f10, Number = 50, Dpc_unk_out = 0xfffffa8003167f10
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f50
KeSetImportanceDpcDpc_unk = 0xfffffa8003167f50, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f50
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167f50, Number = 51, Dpc_unk_out = 0xfffffa8003167f50
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167f90
KeSetImportanceDpcDpc_unk = 0xfffffa8003167f90, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167f90
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167f90, Number = 52, Dpc_unk_out = 0xfffffa8003167f90
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003167fd0
KeSetImportanceDpcDpc_unk = 0xfffffa8003167fd0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003167fd0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003167fd0, Number = 53, Dpc_unk_out = 0xfffffa8003167fd0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168010
KeSetImportanceDpcDpc_unk = 0xfffffa8003168010, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168010
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168010, Number = 54, Dpc_unk_out = 0xfffffa8003168010
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168050
KeSetImportanceDpcDpc_unk = 0xfffffa8003168050, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168050
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168050, Number = 55, Dpc_unk_out = 0xfffffa8003168050
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168090
KeSetImportanceDpcDpc_unk = 0xfffffa8003168090, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168090
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168090, Number = 56, Dpc_unk_out = 0xfffffa8003168090
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031680d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031680d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031680d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031680d0, Number = 57, Dpc_unk_out = 0xfffffa80031680d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168110
KeSetImportanceDpcDpc_unk = 0xfffffa8003168110, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168110
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168110, Number = 58, Dpc_unk_out = 0xfffffa8003168110
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168150
KeSetImportanceDpcDpc_unk = 0xfffffa8003168150, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168150
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168150, Number = 59, Dpc_unk_out = 0xfffffa8003168150
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168190
KeSetImportanceDpcDpc_unk = 0xfffffa8003168190, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168190
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168190, Number = 60, Dpc_unk_out = 0xfffffa8003168190
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa80031681d0
KeSetImportanceDpcDpc_unk = 0xfffffa80031681d0, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa80031681d0
KeSetTargetProcessorDpcDpc_unk = 0xfffffa80031681d0, Number = 61, Dpc_unk_out = 0xfffffa80031681d0
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168210
KeSetImportanceDpcDpc_unk = 0xfffffa8003168210, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168210
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168210, Number = 62, Dpc_unk_out = 0xfffffa8003168210
KeInitializeDpcDeferredRoutine_unk = 0xfffff88003908690, DeferredContext_ptr = 0xfffffa8001927000, Dpc_unk_out = 0xfffffa8003168250
KeSetImportanceDpcDpc_unk = 0xfffffa8003168250, Importance_unk = 0x2, Dpc_unk_out = 0xfffffa8003168250
KeSetTargetProcessorDpcDpc_unk = 0xfffffa8003168250, Number = 63, Dpc_unk_out = 0xfffffa8003168250
Kernel Graph 2
No Kernel Graph Available
Code Block #2 ( EP #2)
+
InformationValue
TriggerIofCallDriver+0x50
Start Address0xfffff88003908980
Execution Path #2 (length: 5, amount: 1, processes: 1)
+
InformationValue
Sequence Length5
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x678, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8001952980
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x20, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa800186dd80
PsGetCurrentProcessIdret_val_unk_out = 0x4cc
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Kernel Graph 3
No Kernel Graph Available
Code Block #3 ( EP #3, #4, #5, #6, #7)
+
InformationValue
TriggerIofCallDriver+0x50
Start Address0xfffff88003908af0
Execution Path #3 (length: 3, amount: 1, processes: 1)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
IoIs32bitProcessIrp_unk = 0xfffffa8002e2ad00, ret_val_out = 0
strncmp_Str1 = The Magic Word!, _Str2 = The Magic Word!, _MaxCount = 0x10, ret_val_out = 0
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Execution Path #4 (length: 7, amount: 1, processes: 1)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
IoIs32bitProcessIrp_unk = 0xfffffa8002e2ad00, ret_val_out = 0
memchr_Buf_ptr = 0xfffffa800316255c, _Val = 0, _MaxCount = 0x20, ret_val_ptr_out = 0xfffffa800316255d
ExAcquireFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0xaf, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa80031626b0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x28, Tag = 0x54525049, ret_val_ptr_out = 0xfffffa8002ed4160
ExReleaseFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Execution Path #5 (length: 4, amount: 1, processes: 1)
+
InformationValue
Sequence Length4
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
IoIs32bitProcessIrp_unk = 0xfffffa8002e2ad00, ret_val_out = 0
ExAcquireFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
ExReleaseFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Execution Path #6 (length: 2, amount: 1, processes: 1)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
IoIs32bitProcessIrp_unk = 0xfffffa8002e2ad00, ret_val_out = 0
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Execution Path #7 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Kernel Graph 4
No Kernel Graph Available
Code Block #4 ( EP #8)
+
InformationValue
TriggerIofCallDriver+0x50
Start Address0xfffff88003908390
Execution Path #8 (length: 7, amount: 1, processes: 1)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 35 (pxinsi64.exe, PID: 1228)1
Sequence
+
SymbolParameters
ExAcquireFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
ExFreePoolWithTagP_ptr = 0xfffffa80031626b0, Tag = 0x0
ExFreePoolWithTagP_ptr = 0xfffffa8002ed4160, Tag = 0x0
ExReleaseFastMutexFastMutex_unk = 0xfffffa8003126588, FastMutex_unk_out = 0xfffffa8003126588
ExFreePoolWithTagP_ptr = 0xfffffa800186dd80, Tag = 0x0
ExFreePoolWithTagP_ptr = 0xfffffa8001952980, Tag = 0x0
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
Kernel Graph 5
No Kernel Graph Available
Code Block #5 ( EP #9)
+
InformationValue
TriggerIopLoadUnloadDriver+0x19
Start Address0xfffff880039088b0
Execution Path #9 (length: 9, amount: 1, processes: 1)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
RtlInitUnicodeStringSourceString = \DosDevices\VBoxDrv, DestinationString_out = \DosDevices\VBoxDrv
IoDeleteSymbolicLinkSymbolicLinkName = \DosDevices\VBoxDrv, ret_val_unk_out = 0x0
KeCancelTimerparam_1_unk = 0xfffffa8003167210, param_1_unk_out = 0xfffffa8003167210, ret_val_out = 0
IoFreeMdlMdl_unk = 0xfffffa8003209a00
MmFreeContiguousMemoryBaseAddress_ptr = 0xfffffa8001927000
ExFreePoolWithTagP_ptr = 0xfffffa8003074780, Tag = 0x0
ExFreePoolWithTagP_ptr = 0xfffffa8003126570, Tag = 0x0
ExFreePoolWithTagP_ptr = 0xfffffa8001f5a870, Tag = 0x0
IoDeleteDeviceDeviceObject_unk = 0xfffffa8003167050
Kernel Graph 6
No Kernel Graph Available
Code Block #6 ( EP #11)
+
InformationValue
TriggerIopLoadDriver+0xa04
Start Address0xfffff88004895be0
Execution Path #11 (length: 603, amount: 1, processes: 1)
+
InformationValue
Sequence Length603
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x10, Tag = 0x4895544, ret_val_ptr_out = 0xfffffa8002ec3a40
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047894b0, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExFreePoolWithTagP_ptr = 0xfffffa8002ec3a40, Tag = 0x4895544
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047897a8, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880047897a8, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
RtlQueryRegistryValuesRelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff88004789780, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
RtlNtStatusToDosErrorStatus_unk = 0x0, ret_val_out = 0x0
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventHandle_ptr_out = 0xfffff88004789810, ret_val_unk_out = 0xc0000034
_snwprintf_Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62
RtlInitUnicodeStringSourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventHandle_ptr_out = 0xfffff88004789810, ret_val_unk_out = 0xc0000034
PsGetVersionMajorVersion_ptr_out = 0xfffff88004789528, MinorVersion_ptr_out = 0xfffff88004789520, BuildNumber_ptr_out = 0x0, CSDVersion_ptr_out = 0x0, ret_val_out = 0
RtlLengthRequiredSidSubAuthorityCount = 0x1, ret_val_out = 0xc
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x44, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a000dbfc00
RtlCreateSecurityDescriptorRevision = 0x1, SecurityDescriptor_unk_out = 0xfffff8a000dbfc00, ret_val_unk_out = 0x0
RtlSetDaclSecurityDescriptorDaclPresent = 1, Dacl_unk = 0x0, DaclDefaulted = 0, SecurityDescriptor_unk_out = 0xfffff8a000dbfc00, ret_val_unk_out = 0x0
ZwCreateEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880047895a0, EventType_unk = 0x0, InitialState = 0, EventHandle_ptr_out = 0xfffff8800486f5b8, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a000dbfc00, Tag = 0x7346744e
PsCreateSystemThreadDesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffff8800482303c, StartContext_ptr = 0xfffff880048708d4, ThreadHandle_ptr_out = 0xfffff88004789818, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x87000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8001bbe000
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789708, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789708, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
RtlQueryRegistryValuesRelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880047896e0, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
RtlNtStatusToDosErrorStatus_unk = 0x0, ret_val_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026ec860, Length = 0x7a0, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003209a00, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8003209a00
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026ed000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x60, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002e556a0
sprintf_Format = %02x, _Dest_out = 65, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 04, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 25, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 88, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 80, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f6, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c3, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003209a00, MemoryDescriptorList_unk_out = 0xfffffa8003209a00
IoFreeMdlMdl_unk = 0xfffffa8003209a00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x4000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789508, ret_val_unk_out = 0xc0000004
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x9658, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f17000
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9658, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff88004789508, ret_val_unk_out = 0x0
_vsnprintfcount = 0x104, format = \SystemRoot\system32\%s, ap_unk = 0xfffff88004789518, string_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_out = 33
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x20a, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f435e0
mbstowcs_Source = \SystemRoot\system32\ntoskrnl.exe, _MaxCount = 0x104, _Dest_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_unk_out = 0x21
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x208, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001635bd0
wcsncpy_Source = \SystemRoot\system32\ntoskrnl.exe, _Count = 0x104, _Dest_out = \SystemRoot\system32\ntoskrnl.exe, ret_val_out = \SystemRoot\system32\ntoskrnl.exe
RtlInitUnicodeStringSourceString = \SystemRoot\system32\ntoskrnl.exe, DestinationString_out = \SystemRoot\system32\ntoskrnl.exe
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880047893b8, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\system32\ntoskrnl.exe, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff88004789390, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880047893a8, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001635bd0, Tag = 0x7346744e
ZwQueryInformationFileFileHandle_unk = 0xffffffff80000824, Length = 0x18, FileInformationClass_unk = 0x5, IoStatusBlock_unk_out = 0xfffff880047893e0, FileInformation_ptr_out = 0xfffff880047893f0, ret_val_unk_out = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x54bfc0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a002000000
ZwReadFileFileHandle_unk = 0xffffffff80000824, Event_unk = 0x0, UserApcRoutine_unk = 0x0, UserApcContext_ptr = 0x0, BufferLength = 0x54bfc0, ByteOffset_ptr = 0xfffff88004789438, ByteOffset = -2, Key_ptr = 0x0, IoStatusBlock_unk_out = 0xfffff88004789400, Buffer_ptr_out = 0xfffff8a002000000, Buffer_deref_data_out = BINARY(offset=108056959,skipped=1,size=0), ret_val_unk_out = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x5e7000, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a002600000
ExFreePoolWithTagP_ptr = 0xfffff8a002000000, Tag = 0x7346744e
ZwCloseHandle_unk = 0x0, ret_val_unk_out = 0xc0000008
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
ExFreePoolWithTagP_ptr = 0xfffff8a001f435e0, Tag = 0x7346744e
ExFreePoolWithTagP_ptr = 0xfffff8a001f17000, Tag = 0x7346744e
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88007fad000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fad000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0xc88, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001f4b010
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa80018506f0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x2c, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002eb0220
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8002eb0200
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8002eb0200
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80000b95c02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
ExFreePoolWithTagP_ptr = 0xfffffa8002eb0220, Tag = 0x7346744e
ExAllocatePoolWithTagPoolType_unk = 0x1, NumberOfBytes_ptr = 0x104, Tag = 0x7346744e, ret_val_ptr_out = 0xfffff8a001858010
ExFreePoolWithTagP_ptr = 0xfffff8a001858010, Tag = 0x7346744e
ZwCloseHandle_unk = 0x0, ret_val_unk_out = 0xc0000008
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800026f6902, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002fc9600
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 54, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 54, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026f6920, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x10, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002ec3a40
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0x28, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa8002eb0220
ExAllocatePoolWithTagPoolType_unk = 0x0, NumberOfBytes_ptr = 0xe0, Tag = 0x7346744e, ret_val_ptr_out = 0xfffffa800202f300
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f5, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 41, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 81, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f5, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 41, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 81, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 41, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 81, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 80, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 41, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 81, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 80, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 64, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 84, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 80, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 64, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 84, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 80, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c5060, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 26, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 45, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 45, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 43, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 45, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 45, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 43, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4920, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 23, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 65, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 04, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 25, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 88, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 90, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f6, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 65, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 04, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 25, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 88, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 90, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f6, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 29, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 54, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 54, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
strncpy_Source = $NtUninstallQ923283$, _Count = 0x64, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
_snwprintf_Count = 0x104, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32
strncpy_Source = fdisk.sys, _Count = 0x64, _Dest_out = fdisk.sys, ret_val_out = fdisk.sys
_snwprintf_Count = 0x104, _Format = %s\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$\fdisk.sys, ret_val_out = 42
RtlInitUnicodeStringSourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff88004788ef0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x2, ShareAccess = 0x0, Disposition = 0x2, CreateOptions = 0x21, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x700000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880047896a0, FileHandle_out = 0xfffffa8002e516c0, IoStatusBlock_unk_out = 0xfffff88004788fa0, ret_val_unk_out = 0xc0000035
_snprintf_Count = 0x64, _Format = %s, _Dest_out = Ultra3, ret_val_out = 6
_snwprintf_Count = 0x104, _Format = \Registry\Machine\System\CurrentControlSet\Services\%S, _Dest_out = \Registry\Machine\System\CurrentControlSet\Services\Ultra3, ret_val_out = 58
RtlInitUnicodeStringSourceString = \Registry\Machine\System\CurrentControlSet\Services\Ultra3, DestinationString_out = \Registry\Machine\System\CurrentControlSet\Services\Ultra3
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
strncpy_Source = $NtUninstallQ923283$, _Count = 0x64, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
_snwprintf_Count = 0x104, _Format = %%SystemRoot%%\%S, _Dest_out = %SystemRoot%\$NtUninstallQ923283$, ret_val_out = 33
strncpy_Source = fdisk_mon.exe, _Count = 0x64, _Dest_out = fdisk_mon.exe, ret_val_out = fdisk_mon.exe
_snwprintf_Count = 0x104, _Format = %s\%S, _Dest_out = %SystemRoot%\$NtUninstallQ923283$\fdisk_mon.exe, ret_val_out = 47
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
ZwFlushKeyKeyHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc8880, StartContext_ptr = 0x0, ThreadHandle_ptr_out = 0xfffff880047895a0, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a000307c00, ThreadHandle_ptr_out = 0xfffff88004789610, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff80000824, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
KeInitializeEventType_unk = 0x0, State = 0, Event_unk_out = 0xfffff88004789610
KeInitializeDpcDeferredRoutine_unk = 0xfffffa8001bc4130, DeferredContext_ptr = 0xfffff88004789610, Dpc_unk_out = 0xfffff88004789630
KeSetImportanceDpcDpc_unk = 0xfffff88004789630, Importance_unk = 0x2, Dpc_unk_out = 0xfffff88004789630
KeSetTargetProcessorDpcDpc_unk = 0xfffff88004789630, Number = 0, Dpc_unk_out = 0xfffff88004789630
KeInsertQueueDpcDpc_unk = 0xfffff88004789630, SystemArgument1_ptr = 0x0, SystemArgument2_ptr = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffff88004789610, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a54200, Length = 0x100, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003209a00
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003209a00, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8003209a00
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800026cc502, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 38, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026cc550, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800026d7502, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026d75f0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ZwOpenKeyDesiredAccess_unk = 0x2, ObjectAttributes_ptr = 0xfffff88004789710, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\System\CurrentControlSet\Control\Session Manager\Memory Management, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880047896c0, KeyHandle_out = 0xffffffff80000824, ret_val_unk_out = 0x0
ZwSetValueKeyKeyHandle_unk = 0xffffffff80000824, ValueName = LargePageMinimum, TitleIndex = 0x0, Type = 0x4, Data_ptr = 0xfffff88004789780, Data = 0xffffffff, DataSize = 0x4, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800026d6102, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026d6180, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002939002, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029390c0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a000307c00, ThreadHandle_ptr_out = 0xfffff88004789740, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
Code Block #7 ( EP #570)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffff8800482303c
Execution Path #570 (length: 2, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsTerminateSystemThreadExitStatus_unk = 0x0
Code Block #8 ( EP #571)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bc8880
Execution Path #571 (length: 2, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8003177620
PsTerminateSystemThreadExitStatus_unk = 0x0
Code Block #9 ( EP #572, #50, #574, #576, #577, #584)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bc88f4
Execution Path #572 (length: 3, amount: 3, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)3
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002f81b50
randret_val_out = 17888
PsTerminateSystemThreadExitStatus_unk = 0x0
Execution Path #50 (length: 2199, amount: 1, processes: 1)
+
InformationValue
Sequence Length2199
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa80030e9a00
randret_val_out = 12425
KeGetCurrentIrqlret_val_unk_out = 0x0
PsCreateSystemThreadDesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System
RtlInitUnicodeStringSourceString = \Device\Null, DestinationString_out = \Device\Null
IoGetDeviceObjectPointerObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObfReferenceObjectObject_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002db2820
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003062510
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa800303a160
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003133510
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 13, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 09, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 31, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 03, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 33, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 7d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 16, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 0c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 29, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par1, ret_val_out = 8
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par2, ret_val_out = 8
_snwprintf_Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62
RtlInitUnicodeStringSourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlQueryRegistryValuesRelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlNtStatusToDosErrorStatus_unk = 0x0, ret_val_out = 0x0
RtlInitUnicodeStringSourceString = \SystemRoot, DestinationString_out = \SystemRoot
ZwOpenSymbolicLinkObjectDesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0
ZwQuerySymbolicLinkObjectSymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0
wcsncpy_Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows
strncpy_Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
_snwprintf_Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20
_snwprintf_Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32
RtlInitUnicodeStringSourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$
ZwOpenFileDesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfReferenceObjectObject_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa
ObfReferenceObjectObject_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa80030e9a00
IoAllocateMdlVirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #574 (length: 38, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa800311f640
randret_val_out = 25331
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0
Execution Path #576 (length: 3, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002fc83c0
randret_val_out = 11502
KeWaitForSingleObjectObject_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0
Execution Path #577 (length: 82, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length82
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8003177620
randret_val_out = 5970
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001b86598
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001820b68
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001e9a6f8
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000
Execution Path #584 (length: 1613, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1613
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002e72880
randret_val_out = 14463
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Code Block #13 ( EP #573)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bdfef4
Execution Path #573 (length: 739, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length739
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -27
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = 63
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0
PsTerminateSystemThreadExitStatus_unk = 0x0
Kernel Graph 7
No Kernel Graph Available
Code Block #10 ( EP #10)
+
InformationValue
TriggerKiRetireDpcList+0x1b5
Start Address0xfffffa8001bc4130
Execution Path #10 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeSetEventEvent_unk = 0xfffff88004789610, Increment_unk = 0x0, Wait = 0
Kernel Graph 8
No Kernel Graph Available
Code Block #11 ( EP #12, #13, #14, #15, #16, #17, #18, #19, #20, #21, #22, #23, #24, #25, #26, #27, #28, #29, #31, #30, #32, #33, #34, #35, #44, #45, #46, #47, #48, #49, #51, #79, #80, #90, #91, #94, #95, #97, #122, #116, #117, #118, #120, #121, #123, #124, #125, #126, #127, #128, #130, #131, #132, #134, #135, #136, #137, #579, #141, #166, #583, #146, #163, #149, #150, #151, #152, #153, #155, #156, #157, #158, #159, #160, #161, #162, #580, #167, #170, #171, #172, #275, #173, #174, #175, #176, #177, #178, #179, #180, #400, #181, #182, #183, #184, #185, #187, #189, #190, #191, #192, #193, #194, #196, #199, #201, #204, #206, #208, #209, #210, #211, #212, #214, #216, #217, #219, #221, #225, #226, #227, #228, #230, #231, #233, #234, #236, #237, #238, #240, #241, #244, #245, #246, #249, #248, #252, #253, #255, #256, #258, #259, #260, #262, #263, #264, #266, #268, #269, #270, #271, #274, #277, #278, #279, #280, #281, #282, #283, #284, #287, #288, #289, #291, #293, #294, #296, #297, #300, #302, #307, #308, #309, #310, #311, #312, #313, #314, #317, #319, #320, #321, #322, #324, #325, #328, #329, #331, #332, #333, #334, #335, #336, #337, #587, #340, #341, #342, #343, #344, #345, #346, #347, #348, #350, #351, #352, #354, #355, #356, #357, #359, #360, #362, #363, #365, #367, #368, #370, #373, #375, #378, #379, #383, #385, #386, #388, #391, #393, #394, #397, #398, #399, #402, #512, #403, #405, #406, #409, #410, #411, #412, #413, #414, #415, #416, #417, #418, #419, #420, #421, #423, #424, #425, #426, #427, #428, #429, #430, #431, #433, #434, #435, #437, #440, #442, #443, #444, #446, #448, #450, #454, #455, #456, #458, #459, #460, #462, #463, #464, #466, #516, #467, #468, #469, #471, #475, #476, #477, #481, #483, #486, #487, #488, #489, #490, #492, #494, #495, #496, #497, #498, #499, #500, #502, #503, #506, #507, #508, #509, #510, #511, #513, #514, #515, #565, #517, #518, #523, #589, #541, #525, #528, #529, #533, #603, #534, #536, #537, #538, #539, #599, #543, #544, #548, #550, #549, #607, #553, #555, #563, #564, #567, #569)
+
InformationValue
TriggerIofCallDriver+0x2
Start Address0xfffffa8001c02000
Execution Path #12 (length: 24, amount: 8, processes: 1)
+
InformationValue
Sequence Length24
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)8
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #13 (length: 6, amount: 82, processes: 4)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)27
Process 18 (svchost.exe, PID: 264)1
Process 4 (csrss.exe, PID: 304)52
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #14 (length: 84, amount: 1, processes: 1)
+
InformationValue
Sequence Length84
Processes
+
ProcessAmount
Process 4 (csrss.exe, PID: 304)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #15 (length: 12, amount: 12, processes: 1)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 4 (csrss.exe, PID: 304)12
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #16 (length: 78, amount: 1, processes: 1)
+
InformationValue
Sequence Length78
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #17 (length: 7, amount: 4157, processes: 32)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)5
Process 2 (System, PID: 4)163
Process 4 (csrss.exe, PID: 304)51
Process 6 (csrss.exe, PID: 364)4
Process 8 (services.exe, PID: 448)43
Process 9 (lsass.exe, PID: 464)208
Process 10 (lsm.exe, PID: 472)13
Process 11 (svchost.exe, PID: 564)152
Process 12 (svchost.exe, PID: 628)73
Process 13 (svchost.exe, PID: 684)329
Process 14 (svchost.exe, PID: 780)38
Process 15 (svchost.exe, PID: 836)285
Process 16 (svchost.exe, PID: 860)664
Process 18 (svchost.exe, PID: 264)1671
Process 19 (spoolsv.exe, PID: 1020)22
Process 20 (svchost.exe, PID: 1040)23
Process 21 (taskhost.exe, PID: 1128)3
Process 23 (explorer.exe, PID: 1244)28
Process 24 (taskeng.exe, PID: 1268)3
Process 25 (svchost.exe, PID: 1692)24
Process 26 (taskeng.exe, PID: 1876)5
Process 27 (searchindexer.exe, PID: 2032)15
Process 28 (searchprotocolhost.exe, PID: 1424)3
Process 31 (mscorsvw.exe, PID: 2128)1
Process 33 (mscorsvw.exe, PID: 2028)108
Process 34 (googleupdate.exe, PID: 2220)53
Process 36 (sppsvc.exe, PID: 248)83
Process 37 (googleupdate.exe, PID: 1000)10
Process 38 (googleupdate.exe, PID: 2496)10
Process 39 (googlecrashhandler.exe, PID: 2460)9
Process 40 (googlecrashhandler64.exe, PID: 2456)48
Process 41 (googleupdate.exe, PID: 2440)10
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x1d0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x8c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880045f6a80, Object_out = 0xfffff8a000c5dc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000c5dc50, ret_val_ptr_out = 0x14
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #18 (length: 3, amount: 1331, processes: 20)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)97
Process 34 (googleupdate.exe, PID: 2220)26
Process 11 (svchost.exe, PID: 564)40
Process 36 (sppsvc.exe, PID: 248)51
Process 37 (googleupdate.exe, PID: 1000)10
Process 38 (googleupdate.exe, PID: 2496)10
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)2
Process 8 (services.exe, PID: 448)26
Process 9 (lsass.exe, PID: 464)1
Process 39 (googlecrashhandler.exe, PID: 2460)9
Process 12 (svchost.exe, PID: 628)30
Process 13 (svchost.exe, PID: 684)10
Process 14 (svchost.exe, PID: 780)27
Process 15 (svchost.exe, PID: 836)52
Process 16 (svchost.exe, PID: 860)222
Process 40 (googlecrashhandler64.exe, PID: 2456)35
Process 18 (svchost.exe, PID: 264)661
Process 20 (svchost.exe, PID: 1040)8
Process 41 (googleupdate.exe, PID: 2440)10
Process 23 (explorer.exe, PID: 1244)4
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1e3b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dba20, Length_ptr = 0x10, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
Execution Path #19 (length: 23, amount: 1, processes: 1)
+
InformationValue
Sequence Length23
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
strncpy_Source = Ultra3, _Count = 0x52, _Dest_out = Ultra3, ret_val_out = Ultra3
strncpy_Source = Ultra3, _Count = 0x52, _Dest_out = Ultra3, ret_val_out = Ultra3
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x364, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880032199e0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219780, Object_out = 0xfffff8a001e9fcc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9fcc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219960, Object_out = 0xfffff8a001e9fcc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9fcc0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #20 (length: 47, amount: 53, processes: 11)
+
InformationValue
Sequence Length47
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Process 34 (googleupdate.exe, PID: 2220)5
Process 36 (sppsvc.exe, PID: 248)15
Process 37 (googleupdate.exe, PID: 1000)3
Process 38 (googleupdate.exe, PID: 2496)3
Process 39 (googlecrashhandler.exe, PID: 2460)3
Process 8 (services.exe, PID: 448)4
Process 41 (googleupdate.exe, PID: 2440)3
Process 13 (svchost.exe, PID: 684)2
Process 16 (svchost.exe, PID: 860)4
Process 40 (googlecrashhandler64.exe, PID: 2456)9
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1e358, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x438f80, Length_ptr = 0x26, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\TEMP, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = TEMP, _String2 = $NtUninstallQ923283$, _MaxCount = 0x3, ret_val_out = 80
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #21 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x36c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880032199e0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219780, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x36c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219960, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #22 (length: 473, amount: 1, processes: 1)
+
InformationValue
Sequence Length473
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1e4f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x438f80, Length_ptr = 0x80, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\Temp, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = ServiceProfiles\NetworkService\AppData\Local\Temp, _String2 = $NtUninstallQ923283$, _MaxCount = 0x30, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = ServiceProfiles\NetworkService\AppData\Local\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2b, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = ServiceProfiles\NetworkService\AppData\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x25, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = ServiceProfiles\NetworkService\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1d, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\NetworkService\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\ServiceProfiles, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = ServiceProfiles, _String2 = $NtUninstallQ923283$, _MaxCount = 0xe, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #23 (length: 20, amount: 94, processes: 12)
+
InformationValue
Sequence Length20
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)21
Process 34 (googleupdate.exe, PID: 2220)8
Process 36 (sppsvc.exe, PID: 248)18
Process 37 (googleupdate.exe, PID: 1000)5
Process 38 (googleupdate.exe, PID: 2496)5
Process 39 (googlecrashhandler.exe, PID: 2460)5
Process 8 (services.exe, PID: 448)4
Process 41 (googleupdate.exe, PID: 2440)5
Process 13 (svchost.exe, PID: 684)3
Process 16 (svchost.exe, PID: 860)10
Process 40 (googlecrashhandler64.exe, PID: 2456)9
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1e218, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x438f80, Length_ptr = 0x1e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
Execution Path #24 (length: 40, amount: 2, processes: 1)
+
InformationValue
Sequence Length40
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xe1e250, Length = 0x7c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
_wcsicmp_Str1 = ServiceProfiles, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0xe1e250, Length = 0x7c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
_wcsicmp_Str1 = ServiceProfiles, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
Execution Path #25 (length: 35, amount: 87, processes: 11)
+
InformationValue
Sequence Length35
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)22
Process 34 (googleupdate.exe, PID: 2220)4
Process 36 (sppsvc.exe, PID: 248)16
Process 37 (googleupdate.exe, PID: 1000)4
Process 38 (googleupdate.exe, PID: 2496)4
Process 39 (googlecrashhandler.exe, PID: 2460)4
Process 8 (services.exe, PID: 448)9
Process 41 (googleupdate.exe, PID: 2440)4
Process 13 (svchost.exe, PID: 684)2
Process 16 (svchost.exe, PID: 860)9
Process 40 (googlecrashhandler64.exe, PID: 2456)9
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x320, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #26 (length: 24, amount: 25, processes: 3)
+
InformationValue
Sequence Length24
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)2
Process 33 (mscorsvw.exe, PID: 2028)19
Process 16 (svchost.exe, PID: 860)4
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\ServiceProfiles\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
Execution Path #27 (length: 2, amount: 686, processes: 17)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)37
Process 34 (googleupdate.exe, PID: 2220)11
Process 36 (sppsvc.exe, PID: 248)22
Process 37 (googleupdate.exe, PID: 1000)3
Process 38 (googleupdate.exe, PID: 2496)3
Process 39 (googlecrashhandler.exe, PID: 2460)3
Process 8 (services.exe, PID: 448)2
Process 41 (googleupdate.exe, PID: 2440)3
Process 11 (svchost.exe, PID: 564)2
Process 12 (svchost.exe, PID: 628)71
Process 13 (svchost.exe, PID: 684)11
Process 14 (svchost.exe, PID: 780)22
Process 15 (svchost.exe, PID: 836)26
Process 16 (svchost.exe, PID: 860)125
Process 40 (googlecrashhandler64.exe, PID: 2456)17
Process 18 (svchost.exe, PID: 264)292
Process 23 (explorer.exe, PID: 1244)36
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1e7f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefd728630, Length_ptr = 0x28, Alignment = 0x2
Execution Path #28 (length: 309, amount: 2, processes: 2)
+
InformationValue
Sequence Length309
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Process 13 (svchost.exe, PID: 684)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1df70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x438f80, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\system32\sppsvc.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\sppsvc.exe, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001a7e670, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001a7e670, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003218c80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #29 (length: 17, amount: 11, processes: 7)
+
InformationValue
Sequence Length17
Processes
+
ProcessAmount
Process 36 (sppsvc.exe, PID: 248)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 8 (services.exe, PID: 448)5
Process 41 (googleupdate.exe, PID: 2440)1
Process 40 (googlecrashhandler64.exe, PID: 2456)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\system32\sppsvc.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\sppsvc.exe, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
Execution Path #31 (length: 14, amount: 83, processes: 13)
+
InformationValue
Sequence Length14
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Process 34 (googleupdate.exe, PID: 2220)1
Process 36 (sppsvc.exe, PID: 248)19
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 8 (services.exe, PID: 448)4
Process 41 (googleupdate.exe, PID: 2440)1
Process 13 (svchost.exe, PID: 684)7
Process 16 (svchost.exe, PID: 860)4
Process 18 (svchost.exe, PID: 264)1
Process 4 (csrss.exe, PID: 304)6
Process 27 (searchindexer.exe, PID: 2032)36
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #30 (length: 18, amount: 101, processes: 7)
+
InformationValue
Sequence Length18
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Process 2 (System, PID: 4)84
Process 36 (sppsvc.exe, PID: 248)10
Process 8 (services.exe, PID: 448)2
Process 13 (svchost.exe, PID: 684)2
Process 18 (svchost.exe, PID: 264)1
Process 20 (svchost.exe, PID: 1040)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #32 (length: 11, amount: 3, processes: 1)
+
InformationValue
Sequence Length11
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)3
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #33 (length: 12, amount: 1, processes: 1)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
Execution Path #34 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001ee9470, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
FltpSynchronizedOperationCompletionret_val_out = 0xc0000016
Execution Path #35 (length: 15, amount: 1, processes: 1)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
Execution Path #44 (length: 19, amount: 24, processes: 7)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)18
Process 4 (csrss.exe, PID: 304)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 41 (googleupdate.exe, PID: 2440)1
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x21cf2d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2ce060, Length_ptr = 0x52, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x130
PsGetCurrentProcessret_val_out = 0xfffffa8002b95b30
strncpy_Source = csrss.exe, _Count = 0x52, _Dest_out = csrss.exe, ret_val_out = csrss.exe
_strnicmp_Str1 = csrss.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
_strnicmp_Str1 = csrss.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x130
_wcsnicmp_String1 = Windows\system32\sppsvc.exe.Config, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\sppsvc.exe.Config, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79
Execution Path #45 (length: 3, amount: 1342, processes: 11)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)6
Process 34 (googleupdate.exe, PID: 2220)2
Process 36 (sppsvc.exe, PID: 248)7
Process 2 (System, PID: 4)7
Process 12 (svchost.exe, PID: 628)2
Process 13 (svchost.exe, PID: 684)1
Process 15 (svchost.exe, PID: 836)120
Process 16 (svchost.exe, PID: 860)309
Process 18 (svchost.exe, PID: 264)862
Process 19 (spoolsv.exe, PID: 1020)22
Process 20 (svchost.exe, PID: 1040)4
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #46 (length: 18, amount: 23, processes: 3)
+
InformationValue
Sequence Length18
Processes
+
ProcessAmount
Process 40 (googlecrashhandler64.exe, PID: 2456)5
Process 34 (googleupdate.exe, PID: 2220)13
Process 4 (csrss.exe, PID: 304)5
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x741740, Length_ptr = 0x68, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Program Files (x86)\Google\Update\CRYPTSP.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
Execution Path #47 (length: 341, amount: 2, processes: 1)
+
InformationValue
Sequence Length341
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\CRYPTSP.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\CRYPTSP.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\SysWOW64\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001ef39e0, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001ef39e0, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8002f9d2f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f9d2f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #48 (length: 32, amount: 97, processes: 5)
+
InformationValue
Sequence Length32
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 33 (mscorsvw.exe, PID: 2028)1
Process 34 (googleupdate.exe, PID: 2220)22
Process 36 (sppsvc.exe, PID: 248)72
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #49 (length: 21, amount: 6, processes: 3)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)4
Process 18 (svchost.exe, PID: 264)1
Process 13 (svchost.exe, PID: 684)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x10
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #51 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #79 (length: 14, amount: 48, processes: 11)
+
InformationValue
Sequence Length14
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Process 34 (googleupdate.exe, PID: 2220)1
Process 36 (sppsvc.exe, PID: 248)17
Process 37 (googleupdate.exe, PID: 1000)3
Process 38 (googleupdate.exe, PID: 2496)3
Process 39 (googlecrashhandler.exe, PID: 2460)3
Process 40 (googlecrashhandler64.exe, PID: 2456)11
Process 41 (googleupdate.exe, PID: 2440)3
Process 13 (svchost.exe, PID: 684)2
Process 16 (svchost.exe, PID: 860)2
Process 27 (searchindexer.exe, PID: 2032)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0xf8
PsGetCurrentProcessret_val_out = 0xfffffa8002519060
strncpy_Source = sppsvc.exe, _Count = 0x52, _Dest_out = sppsvc.exe, ret_val_out = sppsvc.exe
_strnicmp_Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030f7401
IoAllocateMdlVirtualAddress_ptr = 0xaf3d0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80030f7401
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
Execution Path #80 (length: 19, amount: 6, processes: 6)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 36 (sppsvc.exe, PID: 248)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 40 (googlecrashhandler64.exe, PID: 2456)1
Process 41 (googleupdate.exe, PID: 2440)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0xf8
PsGetCurrentProcessret_val_out = 0xfffffa8002519060
strncpy_Source = sppsvc.exe, _Count = 0x52, _Dest_out = sppsvc.exe, ret_val_out = sppsvc.exe
_strnicmp_Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = sppsvc.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030f7401
IoAllocateMdlVirtualAddress_ptr = 0xaf450, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80030f7401
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xaf030, Length = 0x408, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa80030f7401
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
Execution Path #90 (length: 4, amount: 38, processes: 1)
+
InformationValue
Sequence Length4
Processes
+
ProcessAmount
Process 2 (System, PID: 4)38
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #91 (length: 7, amount: 40, processes: 1)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 2 (System, PID: 4)40
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #94 (length: 488, amount: 1, processes: 1)
+
InformationValue
Sequence Length488
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1f0f4b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3c96a20, Length_ptr = 0x60, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\User\AppData\Local\Temp\BITB106.tmp, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\Local\Temp\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\Local\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\AppData\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\User\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Users\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee6d70, Object_out = 0xfffffa80031632b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031632b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
Execution Path #95 (length: 1, amount: 33, processes: 2)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)31
Process 11 (svchost.exe, PID: 564)2
Sequence
+
SymbolParameters
ExGetPreviousModeret_val_unk_out = 0xfffffa8001fbc300
Execution Path #97 (length: 317, amount: 1, processes: 1)
+
InformationValue
Sequence Length317
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x49e9c0, Length_ptr = 0x4e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\RpcRtRemote.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\RpcRtRemote.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x17, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001eedc00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001eedc00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = SysWOW64, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dcc80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #122 (length: 79, amount: 1, processes: 1)
+
InformationValue
Sequence Length79
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747b1b68, Length_ptr = 0x4a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b55e90, Length_ptr = 0x92, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b55fda, Length_ptr = 0x90, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b55fda, Length_ptr = 0x90, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x228, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001a27fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a27fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x23c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003120b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003120b50, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #116 (length: 6, amount: 105, processes: 5)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)12
Process 18 (svchost.exe, PID: 264)83
Process 36 (sppsvc.exe, PID: 248)4
Process 34 (googleupdate.exe, PID: 2220)2
Process 15 (svchost.exe, PID: 836)4
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x34be988, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x34be9d0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
Execution Path #117 (length: 13, amount: 220, processes: 7)
+
InformationValue
Sequence Length13
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Process 2 (System, PID: 4)119
Process 36 (sppsvc.exe, PID: 248)1
Process 34 (googleupdate.exe, PID: 2220)2
Process 15 (svchost.exe, PID: 836)4
Process 16 (svchost.exe, PID: 860)12
Process 18 (svchost.exe, PID: 264)81
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004486a80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #118 (length: 13, amount: 297, processes: 3)
+
InformationValue
Sequence Length13
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)60
Process 18 (svchost.exe, PID: 264)223
Process 15 (svchost.exe, PID: 836)14
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xba
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x34beb00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004265b00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004265b00, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb9
Execution Path #120 (length: 10, amount: 3, processes: 3)
+
InformationValue
Sequence Length10
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 33 (mscorsvw.exe, PID: 2028)1
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa800283a5f0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa800283a502, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #121 (length: 6, amount: 27, processes: 3)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)6
Process 18 (svchost.exe, PID: 264)19
Process 15 (svchost.exe, PID: 836)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xba
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb9
Execution Path #123 (length: 42, amount: 1, processes: 1)
+
InformationValue
Sequence Length42
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbf8, Length_ptr = 0x74, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbf8, Length_ptr = 0x72, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbf8, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e234, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #124 (length: 198, amount: 1, processes: 1)
+
InformationValue
Sequence Length198
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747830, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\system32\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbc0, Length_ptr = 0x74, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbc0, Length_ptr = 0x72, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189dbc0, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e1fc, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #125 (length: 126, amount: 1, processes: 1)
+
InformationValue
Sequence Length126
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x747bc8, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\system32\propsys.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\propsys.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #126 (length: 114, amount: 1, processes: 1)
+
InformationValue
Sequence Length114
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7497e0, Length_ptr = 0x8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f308, Length_ptr = 0x28, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f308, Length_ptr = 0xa0, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7497e0, Length_ptr = 0x8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x75884990, Length_ptr = 0x76, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x748bb0, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76d0e038, Length_ptr = 0xc, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f3e0, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x250, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f428, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x254, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f408, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x727b80, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f560, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b42c88, Length_ptr = 0x14, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #127 (length: 486, amount: 1, processes: 1)
+
InformationValue
Sequence Length486
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b4277c, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749c58, Length_ptr = 0x8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e314, Length_ptr = 0x28, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e314, Length_ptr = 0xa0, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749c58, Length_ptr = 0x8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x75884990, Length_ptr = 0x76, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x748c28, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76d0e038, Length_ptr = 0xc, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e3ec, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e434, Length_ptr = 0x0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x264, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b441fc, Length_ptr = 0xc, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec1850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec1850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e3b4, Length_ptr = 0x76, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b43308, Length_ptr = 0xe, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f420, Length_ptr = 0x76, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001832540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001832540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f420, Length_ptr = 0x76, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f374, Length_ptr = 0x88, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xc4, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749d28, Length_ptr = 0xc, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749d28, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd340, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd340, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189f2dc, Length_ptr = 0x94, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x9
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x74a0a0, Length_ptr = 0x72, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Program Files (x86)\Google\Update\GoogleUpdate.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
IoAllocateMdlVirtualAddress_ptr = 0x49e188, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x49ea10, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
IoAllocateMdlVirtualAddress_ptr = 0x189f388, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000d29780, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29780, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x260, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #128 (length: 32, amount: 1, processes: 1)
+
InformationValue
Sequence Length32
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x751260, Length_ptr = 0x62, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #130 (length: 60, amount: 1, processes: 1)
+
InformationValue
Sequence Length60
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0x8e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030dd501
IoAllocateMdlVirtualAddress_ptr = 0xfde2d8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80030dd501
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfdeb60, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa80030dd501
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030dd501
IoAllocateMdlVirtualAddress_ptr = 0x16ff578, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80030dd501
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x290, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x13
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #131 (length: 4, amount: 1, processes: 1)
+
InformationValue
Sequence Length4
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
PsGetCurrentThreadIdret_val_unk_out = 0x9c8
Execution Path #132 (length: 9, amount: 1, processes: 1)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 37 (googleupdate.exe, PID: 1000)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002b1dec0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #134 (length: 459, amount: 2, processes: 1)
+
InformationValue
Sequence Length459
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#FDC#GENERIC_FLOPPY_DRIVE#5&e9e2334&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomHL-DT-ST_DVD-ROM_GDR-T10N_______________1.05____#5&23a61b21&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomHL-DT-ST_DVD-ROM_GDR-T10N_______________1.05____#5&28836b88&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&2770a7af&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.2.____#5&3a2a5854&0&1.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.3.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.4.____#5&2770a7af&0&0.0.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#IDE#CdRomQEMU_QEMU_DVD-ROM_______________________2.4.____#5&2770a7af&0&0.1.0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{1181b660-d211-11e4-b006-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{1181b660-d211-11e4-b006-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000000000007E00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#000000046528EC00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000001E628B7200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#00000020D3A1E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#00000020F3026800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#000000211262E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{846ee343-7039-11de-9d20-806e6f6e6963}#0000002131C36800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000000000007E00#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#000000075343E000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000001E628B7200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#00000020D3A1E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#00000020F3026800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#000000211262E800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{d5e2ffe2-f518-11df-a5c1-806e6f6e6963}#0000002131C36800#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{fb2b09e0-bdf0-11e4-97d2-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#Volume#{fb2b09e0-bdf0-11e4-97d2-806e6f6e6963}#0000000006500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT1#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT10#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT11#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT12#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT13#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT14#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT15#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT16#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT2#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT3#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT4#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT5#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT6#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT7#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT8#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ##?#STORAGE#VOLUMESNAPSHOT#HARDDISKVOLUMESNAPSHOT9#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #135 (length: 39, amount: 43, processes: 1)
+
InformationValue
Sequence Length39
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)43
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #136 (length: 12, amount: 590, processes: 5)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)51
Process 34 (googleupdate.exe, PID: 2220)4
Process 11 (svchost.exe, PID: 564)89
Process 13 (svchost.exe, PID: 684)8
Process 14 (svchost.exe, PID: 780)438
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #137 (length: 49, amount: 2, processes: 1)
+
InformationValue
Sequence Length49
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #579 (length: 96, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length96
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800326b260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800326b260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x218, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8002e031b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e031b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x204, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000dbf3c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000dbf3c0, ret_val_ptr_out = 0x25
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76401ab8, Length_ptr = 0x7e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76401a90, Length_ptr = 0x24, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x764019a0, Length_ptr = 0x3c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x764019a0, Length_ptr = 0x3c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x290, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003162da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003162da0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x294, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80030dcd40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030dcd40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa80031f6700, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031f6700, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003124b10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003124b10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #141 (length: 60, amount: 1, processes: 1)
+
InformationValue
Sequence Length60
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwSetEventEventHandle_unk = 0xffffffff800006d8, PreviousState_ptr_out = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c200
strncpy_Source = system, _Count = 0x52, _Dest_out = system, ret_val_out = system
_snprintf_Count = 0x52, _Format = %s#2, _Dest_out = system#2, ret_val_out = 8
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
Execution Path #166 (length: 44, amount: 1, processes: 1)
+
InformationValue
Sequence Length44
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x8bc400, Length_ptr = 0x12, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002e2ada8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002e2ada8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002e2ada8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002e2ada8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
Execution Path #583 (length: 11085, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length11085
Processes
+
ProcessAmount
Process 37 (googleupdate.exe, PID: 1000)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d7d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d400, Object_out = 0xfffff8a001e55520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e55520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d280, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0xa
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x5c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800464d388, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800464d408, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d030, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007f8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800464d120, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000ebc801, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e630, Length_ptr = 0xa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800464d380, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x8
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x433558, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x7
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x433578, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x6
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x433598, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4335e0, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a7e6c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a7e6c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12d228, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464d4b0, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001efa800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7588a364, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x435250, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x38ed08, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x435730, Length_ptr = 0x34, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f128, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001efa800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0x8e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f1d0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a11930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a11930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001f18340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x435970, Length_ptr = 0x34, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86), _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xc8, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xc8, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x434e78, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x434f00, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4359a0, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4359a0, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a000beffc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000beffc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4359a0, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f030, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a000be7eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000be7eb0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f030, Length_ptr = 0x14, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x435da0, Length_ptr = 0x66, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffff8a001a44480, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a44480, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800464da80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f3d0, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x435da0, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #146 (length: 186, amount: 2, processes: 1)
+
InformationValue
Sequence Length186
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\System32\drivers\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\System32\drivers\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f3ec00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f3ec00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004682720, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #163 (length: 4428, amount: 1, processes: 1)
+
InformationValue
Sequence Length4428
Processes
+
ProcessAmount
Process 14 (svchost.exe, PID: 780)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x37c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff88002ad6950, Object_out = 0xfffff8a001b806b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b806b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x37c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002ad6958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007b0, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff88002ad69d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET CLR Data, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET CLR Networking, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET CLR Networking 4.0.0.0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET Data Provider for Oracle, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET Data Provider for SqlServer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NET Memory Cache 4.0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = .NETFramework, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -39
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1394ohci, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ACPI, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AcpiPmi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = adp94xx, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = adpahci, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = adpu320, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = adsi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AeLookupSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AFD, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = agp440, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ALG, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = aliide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = amdide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AmdK8, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AmdPPM, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = amdsata, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = amdsbs, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = amdxata, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AppID, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AppIDSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Appinfo, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AppMgmt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = arc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = arcsas, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ASP.NET, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ASP.NET_4.0.30319, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = aspnet_state, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AsyncMac, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = atapi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AudioEndpointBuilder, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AudioSrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AxInstSV, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = b06bdrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = b57nd60a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BattC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BDESVC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Beep, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BFE, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BITS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = blbdrive, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = bowser, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BrFiltLo, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BrFiltUp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Browser, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Brserid, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BrSerWdm, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BrUsbMdm, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BrUsbSer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BTHMODEM, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BTHPORT, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = bthserv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = cdfs, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = cdrom, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CertPropSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = circlass, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CLFS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = clr_optimization_v2.0.50727_32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = clr_optimization_v2.0.50727_64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = clr_optimization_v4.0.30319_32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = clr_optimization_v4.0.30319_64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CmBatt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = cmdide, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CNG, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Compbatt, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CompositeBus, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = COMSysApp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = crcdisk, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = crypt32, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 14
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CryptSvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CSC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CscService, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = DCLocator, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = DcomLaunch, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = defragsvc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = DfsC, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Dhcp, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = discache, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Disk, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = dmvsc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Dnscache, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = dot3svc, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = DPS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = DXGKrnl, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -17
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = EapHost, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ebdrv, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = EFS, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehRecvr, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehSched, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = elxstor, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ErrDev, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b0, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #149 (length: 25, amount: 4, processes: 1)
+
InformationValue
Sequence Length25
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)4
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x224, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880045ada80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #150 (length: 12, amount: 3, processes: 1)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
Execution Path #151 (length: 9, amount: 7, processes: 3)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)2
Process 2 (System, PID: 4)1
Process 14 (svchost.exe, PID: 780)4
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #152 (length: 55, amount: 4, processes: 1)
+
InformationValue
Sequence Length55
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)4
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880045ad340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #153 (length: 95, amount: 1, processes: 1)
+
InformationValue
Sequence Length95
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002ff7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ff7530, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16ff754, Length_ptr = 0x94, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8003285410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003285410, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xfde268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16ff754, Length_ptr = 0x94, Alignment = 0x2
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x74a3f0, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #155 (length: 6, amount: 4, processes: 1)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 2 (System, PID: 4)4
Sequence
+
SymbolParameters
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65b00
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffffa80018b0200, Object_ptr_out = 0xfffff88004683400, Object_out = 0xfffff8a001a44460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a44460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #156 (length: 8, amount: 2, processes: 1)
+
InformationValue
Sequence Length8
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #157 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004683430, Object_out = 0xfffffa80030ba930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ba930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #158 (length: 6, amount: 4, processes: 1)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 2 (System, PID: 4)4
Sequence
+
SymbolParameters
_wcsnicmp_String1 = fastfat, _String2 = netbt, _MaxCount = 0x7, ret_val_out = -8
_wcsnicmp_String1 = fastfat, _String2 = afd, _MaxCount = 0x7, ret_val_out = 5
_wcsnicmp_String1 = fastfat, _String2 = Null, _MaxCount = 0x7, ret_val_out = -8
_wcsnicmp_String1 = fastfat, _String2 = Beep, _MaxCount = 0x7, ret_val_out = 4
_wcsnicmp_String1 = fastfat, _String2 = tcpip, _MaxCount = 0x7, ret_val_out = -14
_wcsnicmp_String1 = fastfat, _String2 = Nsiproxy, _MaxCount = 0x7, ret_val_out = -8
Execution Path #159 (length: 118, amount: 1, processes: 1)
+
InformationValue
Sequence Length118
Processes
+
ProcessAmount
Process 13 (svchost.exe, PID: 684)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff88002a60950, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xe0, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a60958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007b8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2650, ResultLength_ptr_out = 0xfffff88002a609d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Application, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = HardwareEvents, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -13
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Internet Explorer, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -12
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Key Management Service, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -10
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Media Center, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Security, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007b8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
PsGetCurrentProcessret_val_out = 0xfffffa8002e08a70
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Windows PowerShell, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a60600, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007b8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a606f0, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff88002a60950, Object_out = 0xfffff8a000d277f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d277f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #160 (length: 17, amount: 10, processes: 1)
+
InformationValue
Sequence Length17
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)10
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64200, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64200, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #161 (length: 14, amount: 13, processes: 2)
+
InformationValue
Sequence Length14
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)11
Process 6 (csrss.exe, PID: 364)2
Sequence
+
SymbolParameters
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x59c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xffffeb9000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88003d64a28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d64a20, Object_out = 0xfffffa80030b5c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030b5c80, ret_val_ptr_out = 0x2
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003d647a0, Object_out = 0xfffffa80030b5c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030b5c80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #162 (length: 61, amount: 1, processes: 1)
+
InformationValue
Sequence Length61
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x20, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880044599e0, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = {430FD4D0-B729-4F61-AA34-91526481799D}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = {4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = {8A69D345-D564-463C-AFF1-A69D9E530F96}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = {FDA71E6F-AC4C-4A00-8B70-9958A68906BF}, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 38
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004459780, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459960, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #580 (length: 343, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length343
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f1321f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f1321f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001e9fe0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001eed7df, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a00030493f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001eda8af, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001a8e02f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a00181ee0f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a0016a11bf, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001ef325f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa80030d8ee0, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x104, _Format = \??\%S\, _Dest_out = \??\Par1\, ret_val_out = 9
_snwprintf_Count = 0xfb, _Format = %S, _Dest_out = system, ret_val_out = 6
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a001f3088f, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000022
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
RtlNtStatusToDosErrorStatus_unk = 0xc0000022, ret_val_out = 0x5
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1fc
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880022c9b38, Interval = -10000000
Execution Path #167 (length: 9, amount: 1, processes: 1)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x8bc400, Length_ptr = 0x1e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
Execution Path #170 (length: 13, amount: 1, processes: 1)
+
InformationValue
Sequence Length13
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x8ebb0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x18f3e0, Length_ptr = 0x10, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002bb4310, PriorityBoost = 0
Execution Path #171 (length: 7, amount: 1, processes: 1)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
Execution Path #172 (length: 19, amount: 6, processes: 1)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)6
Sequence
+
SymbolParameters
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x108, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800447fa28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800447fa20, Object_out = 0xfffffa8003156f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003156f20, ret_val_ptr_out = 0x2
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0xb0c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800447f7a0, Object_out = 0xfffffa8003156f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003156f20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8003227378, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8003227378, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
Execution Path #275 (length: 8, amount: 6, processes: 1)
+
InformationValue
Sequence Length8
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)6
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8003227378, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8003227378, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
Execution Path #173 (length: 21, amount: 103, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 2 (System, PID: 4)103
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #174 (length: 15, amount: 15, processes: 3)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Process 36 (sppsvc.exe, PID: 248)8
Process 13 (svchost.exe, PID: 684)5
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #175 (length: 322, amount: 2, processes: 1)
+
InformationValue
Sequence Length322
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3373b0, Length_ptr = 0x98, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64\v4.0.30319\ngenofflinequeuelock.dat, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64\v4.0.30319\ngenofflinequeuelock.dat, _String2 = $NtUninstallQ923283$, _MaxCount = 0x3c, ret_val_out = 73
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64\v4.0.30319, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64\v4.0.30319, _String2 = $NtUninstallQ923283$, _MaxCount = 0x23, ret_val_out = 73
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x18, ret_val_out = 73
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET, _String2 = $NtUninstallQ923283$, _MaxCount = 0xc, ret_val_out = 73
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #176 (length: 5, amount: 35, processes: 5)
+
InformationValue
Sequence Length5
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Process 18 (svchost.exe, PID: 264)29
Process 13 (svchost.exe, PID: 684)1
Process 14 (svchost.exe, PID: 780)1
Process 15 (svchost.exe, PID: 836)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcae568, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaec08, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ExGetPreviousModeret_val_unk_out = 0xfffffa800328b701
ProbeForReadAddress_ptr = 0xcae638, Length_ptr = 0x4, Alignment = 0x1
Execution Path #177 (length: 38, amount: 3, processes: 2)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #178 (length: 3268, amount: 1, processes: 1)
+
InformationValue
Sequence Length3268
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualC, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualC, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #179 (length: 58, amount: 17, processes: 1)
+
InformationValue
Sequence Length58
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)17
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f186d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #180 (length: 2, amount: 13, processes: 4)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)7
Process 2 (System, PID: 4)4
Process 20 (svchost.exe, PID: 1040)1
Process 26 (taskeng.exe, PID: 1876)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x660
Execution Path #400 (length: 607, amount: 1, processes: 1)
+
InformationValue
Sequence Length607
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x528, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1a8f078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1a8f078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1a8e528, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1ec29c0, Length_ptr = 0x10, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002f2bc40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f2bc40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8dde0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefa873270, Length_ptr = 0x1c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x594, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002f2bc40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f2bc40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8f058, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb6
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb5
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb6
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000b8cb60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b8cb60, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xb5
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb1e00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb1e00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #181 (length: 124, amount: 14, processes: 1)
+
InformationValue
Sequence Length124
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)14
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30e6d0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #182 (length: 212, amount: 15, processes: 1)
+
InformationValue
Sequence Length212
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)15
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35b6c0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35b880, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #183 (length: 248, amount: 15, processes: 1)
+
InformationValue
Sequence Length248
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)15
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ba40, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35bc00, Length_ptr = 0xd6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #184 (length: 124, amount: 53, processes: 1)
+
InformationValue
Sequence Length124
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)53
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35bf80, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #185 (length: 93, amount: 3, processes: 1)
+
InformationValue
Sequence Length93
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35c140, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #187 (length: 96, amount: 1, processes: 1)
+
InformationValue
Sequence Length96
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35c4c0, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
Execution Path #189 (length: 98, amount: 2, processes: 1)
+
InformationValue
Sequence Length98
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35c840, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #190 (length: 114, amount: 5, processes: 1)
+
InformationValue
Sequence Length114
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)5
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35cae0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #191 (length: 36, amount: 18, processes: 1)
+
InformationValue
Sequence Length36
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)18
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #192 (length: 88, amount: 22, processes: 1)
+
InformationValue
Sequence Length88
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)22
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37abc0, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #193 (length: 160, amount: 10, processes: 1)
+
InformationValue
Sequence Length160
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)10
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38acb0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #194 (length: 113, amount: 1, processes: 1)
+
InformationValue
Sequence Length113
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38af50, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #196 (length: 91, amount: 1, processes: 1)
+
InformationValue
Sequence Length91
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38b810, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
Execution Path #199 (length: 96, amount: 1, processes: 1)
+
InformationValue
Sequence Length96
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3aac80, Length_ptr = 0x130, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #201 (length: 34, amount: 1, processes: 1)
+
InformationValue
Sequence Length34
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
Execution Path #204 (length: 719, amount: 1, processes: 1)
+
InformationValue
Sequence Length719
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9230, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9430, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9630, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9830, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37baa0, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e71f0, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #206 (length: 136, amount: 1, processes: 1)
+
InformationValue
Sequence Length136
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37bcc0, Length_ptr = 0x106, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
Execution Path #208 (length: 127, amount: 1, processes: 1)
+
InformationValue
Sequence Length127
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37bee0, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f23bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f23bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37c100, Length_ptr = 0xfc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #209 (length: 25, amount: 14, processes: 2)
+
InformationValue
Sequence Length25
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Process 20 (svchost.exe, PID: 1040)13
Sequence
+
SymbolParameters
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x41c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a96a28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a96a20, Object_out = 0xfffffa8002ff56d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ff56d0, ret_val_ptr_out = 0x4
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a967a0, Object_out = 0xfffffa8002ff56d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ff56d0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #210 (length: 261, amount: 1, processes: 1)
+
InformationValue
Sequence Length261
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3a5cb0, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f43501, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf5a7d0, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
Execution Path #211 (length: 195, amount: 1, processes: 1)
+
InformationValue
Sequence Length195
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9a30, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #212 (length: 33, amount: 1, processes: 1)
+
InformationValue
Sequence Length33
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #214 (length: 189, amount: 1, processes: 1)
+
InformationValue
Sequence Length189
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3da430, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf7e890, Length_ptr = 0xfc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
Execution Path #216 (length: 19, amount: 1, processes: 1)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #217 (length: 105, amount: 1, processes: 1)
+
InformationValue
Sequence Length105
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf71e80, Length_ptr = 0x108, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #219 (length: 63, amount: 1, processes: 1)
+
InformationValue
Sequence Length63
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dac30, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #221 (length: 52, amount: 1, processes: 1)
+
InformationValue
Sequence Length52
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf7ede0, Length_ptr = 0xfe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #225 (length: 184, amount: 1, processes: 1)
+
InformationValue
Sequence Length184
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc1d80, Length_ptr = 0x152, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #226 (length: 136, amount: 1, processes: 1)
+
InformationValue
Sequence Length136
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf7b820, Length_ptr = 0x13c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #227 (length: 16, amount: 1, processes: 1)
+
InformationValue
Sequence Length16
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf7bac0, Length_ptr = 0x138, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
Execution Path #228 (length: 176, amount: 1, processes: 1)
+
InformationValue
Sequence Length176
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc4750, Length_ptr = 0x134, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f233b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f233b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #230 (length: 85, amount: 2, processes: 1)
+
InformationValue
Sequence Length85
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfdf660, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #231 (length: 282, amount: 1, processes: 1)
+
InformationValue
Sequence Length282
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff43a0, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dae30, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
Execution Path #233 (length: 35, amount: 1, processes: 1)
+
InformationValue
Sequence Length35
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #234 (length: 95, amount: 1, processes: 1)
+
InformationValue
Sequence Length95
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc2d90, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #236 (length: 243, amount: 1, processes: 1)
+
InformationValue
Sequence Length243
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc2f70, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #237 (length: 25, amount: 1, processes: 1)
+
InformationValue
Sequence Length25
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc1d50, Length_ptr = 0x120, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #238 (length: 23, amount: 1, processes: 1)
+
InformationValue
Sequence Length23
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #240 (length: 136, amount: 2, processes: 1)
+
InformationValue
Sequence Length136
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc49d0, Length_ptr = 0x128, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #241 (length: 52, amount: 1, processes: 1)
+
InformationValue
Sequence Length52
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc4ed0, Length_ptr = 0x12a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #244 (length: 48, amount: 3, processes: 1)
+
InformationValue
Sequence Length48
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #245 (length: 121, amount: 3, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dc430, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #246 (length: 38, amount: 4, processes: 1)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)4
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dc630, Length_ptr = 0xec, Alignment = 0x2
Execution Path #249 (length: 127, amount: 1, processes: 1)
+
InformationValue
Sequence Length127
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfe07e0, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
Execution Path #248 (length: 11, amount: 1, processes: 1)
+
InformationValue
Sequence Length11
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002e58650
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002e58602, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #252 (length: 226, amount: 1, processes: 1)
+
InformationValue
Sequence Length226
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfe0d20, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff6860, Length_ptr = 0x96, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #253 (length: 57, amount: 2, processes: 1)
+
InformationValue
Sequence Length57
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1007800, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #255 (length: 248, amount: 9, processes: 1)
+
InformationValue
Sequence Length248
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)9
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3dc830, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x10371f0, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #256 (length: 286, amount: 1, processes: 1)
+
InformationValue
Sequence Length286
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc4050, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1047a50, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #258 (length: 56, amount: 3, processes: 1)
+
InformationValue
Sequence Length56
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #259 (length: 26, amount: 1, processes: 1)
+
InformationValue
Sequence Length26
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #260 (length: 43, amount: 1, processes: 1)
+
InformationValue
Sequence Length43
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1045860, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
Execution Path #262 (length: 377, amount: 1, processes: 1)
+
InformationValue
Sequence Length377
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1045ba0, Length_ptr = 0xc4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1007e20, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144c420, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #263 (length: 8, amount: 3, processes: 2)
+
InformationValue
Sequence Length8
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x448
Execution Path #264 (length: 226, amount: 1, processes: 1)
+
InformationValue
Sequence Length226
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1046220, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x10463c0, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #266 (length: 167, amount: 1, processes: 1)
+
InformationValue
Sequence Length167
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff74c0, Length_ptr = 0xf8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
Execution Path #268 (length: 168, amount: 2, processes: 1)
+
InformationValue
Sequence Length168
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144c720, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #269 (length: 10, amount: 5, processes: 1)
+
InformationValue
Sequence Length10
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)5
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #270 (length: 134, amount: 7, processes: 1)
+
InformationValue
Sequence Length134
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)7
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1466500, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #271 (length: 6, amount: 1, processes: 1)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Execution Path #274 (length: 271, amount: 1, processes: 1)
+
InformationValue
Sequence Length271
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14758b0, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104dad0, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
Execution Path #277 (length: 408, amount: 3, processes: 1)
+
InformationValue
Sequence Length408
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104df80, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1478350, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x10087c0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #278 (length: 464, amount: 1, processes: 1)
+
InformationValue
Sequence Length464
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1008de0, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1471940, Length_ptr = 0x92, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148bdb0, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1008fa0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #279 (length: 540, amount: 1, processes: 1)
+
InformationValue
Sequence Length540
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14a9600, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14ab930, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14a98a0, Length_ptr = 0xd6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1499d00, Length_ptr = 0x9e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #280 (length: 446, amount: 1, processes: 1)
+
InformationValue
Sequence Length446
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144cf20, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14b04e0, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14a9d00, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #281 (length: 258, amount: 1, processes: 1)
+
InformationValue
Sequence Length258
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104e610, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf72540, Length_ptr = 0x108, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #282 (length: 168, amount: 1, processes: 1)
+
InformationValue
Sequence Length168
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14aa080, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #283 (length: 426, amount: 1, processes: 1)
+
InformationValue
Sequence Length426
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14b0d20, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144d120, Length_ptr = 0xf6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14ac7d0, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #284 (length: 70, amount: 1, processes: 1)
+
InformationValue
Sequence Length70
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14aa320, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
Execution Path #287 (length: 138, amount: 1, processes: 1)
+
InformationValue
Sequence Length138
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14cd980, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f187d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #288 (length: 107, amount: 5, processes: 1)
+
InformationValue
Sequence Length107
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)5
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff7d40, Length_ptr = 0xf8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #289 (length: 117, amount: 1, processes: 1)
+
InformationValue
Sequence Length117
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14ad190, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #291 (length: 39, amount: 1, processes: 1)
+
InformationValue
Sequence Length39
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #293 (length: 46, amount: 3, processes: 1)
+
InformationValue
Sequence Length46
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #294 (length: 113, amount: 1, processes: 1)
+
InformationValue
Sequence Length113
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14e2020, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001504010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #296 (length: 224, amount: 1, processes: 1)
+
InformationValue
Sequence Length224
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14fc480, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0013cf010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bcb401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144d520, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #297 (length: 130, amount: 1, processes: 1)
+
InformationValue
Sequence Length130
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14de6f0, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Execution Path #300 (length: 332, amount: 1, processes: 1)
+
InformationValue
Sequence Length332
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x150dfa0, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144d720, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1511b20, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #302 (length: 37, amount: 1, processes: 1)
+
InformationValue
Sequence Length37
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
Execution Path #307 (length: 151, amount: 2, processes: 1)
+
InformationValue
Sequence Length151
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1527f20, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #308 (length: 382, amount: 1, processes: 1)
+
InformationValue
Sequence Length382
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1528600, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144db20, Length_ptr = 0xee, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15106a0, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #309 (length: 38, amount: 1, processes: 1)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #310 (length: 436, amount: 1, processes: 1)
+
InformationValue
Sequence Length436
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf72780, Length_ptr = 0x112, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d9c40, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff8180, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #311 (length: 648, amount: 1, processes: 1)
+
InformationValue
Sequence Length648
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d9f10, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1528fa0, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144dd20, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14cac20, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1529470, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #312 (length: 284, amount: 4, processes: 1)
+
InformationValue
Sequence Length284
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)4
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144df20, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15128f0, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #313 (length: 372, amount: 1, processes: 1)
+
InformationValue
Sequence Length372
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff83a0, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15490a0, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15493e0, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #314 (length: 216, amount: 1, processes: 1)
+
InformationValue
Sequence Length216
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15437e0, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15497f0, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #317 (length: 121, amount: 1, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14def70, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #319 (length: 144, amount: 1, processes: 1)
+
InformationValue
Sequence Length144
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1560030, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #320 (length: 312, amount: 2, processes: 1)
+
InformationValue
Sequence Length312
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155da40, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f00bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ce8201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14df4b0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bae010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #321 (length: 224, amount: 1, processes: 1)
+
InformationValue
Sequence Length224
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155e750, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #322 (length: 375, amount: 1, processes: 1)
+
InformationValue
Sequence Length375
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155f0f0, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15603f0, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155fa90, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
Execution Path #324 (length: 191, amount: 1, processes: 1)
+
InformationValue
Sequence Length191
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1575fe0, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144e520, Length_ptr = 0xf6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #325 (length: 302, amount: 1, processes: 1)
+
InformationValue
Sequence Length302
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x157d1b0, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf729c0, Length_ptr = 0x116, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Execution Path #328 (length: 336, amount: 3, processes: 1)
+
InformationValue
Sequence Length336
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x158a450, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1561020, Length_ptr = 0xe4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1577d20, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #329 (length: 825, amount: 1, processes: 1)
+
InformationValue
Sequence Length825
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a0040, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a0520, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001504010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0018447d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0013cf401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a0930, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a0c70, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a1080, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a1220, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14dfc90, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Execution Path #331 (length: 400, amount: 1, processes: 1)
+
InformationValue
Sequence Length400
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a3740, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15615c0, Length_ptr = 0xe6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x157ade0, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #332 (length: 496, amount: 2, processes: 1)
+
InformationValue
Sequence Length496
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144eb20, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15d1b60, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15481b0, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1548350, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #333 (length: 90, amount: 1, processes: 1)
+
InformationValue
Sequence Length90
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1561a70, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
Execution Path #334 (length: 372, amount: 1, processes: 1)
+
InformationValue
Sequence Length372
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144ef20, Length_ptr = 0xee, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15d6ea0, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144f120, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #335 (length: 108, amount: 2, processes: 1)
+
InformationValue
Sequence Length108
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15d80a0, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0e7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #336 (length: 15, amount: 1, processes: 1)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #337 (length: 139, amount: 1, processes: 1)
+
InformationValue
Sequence Length139
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160f100, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
Execution Path #587 (length: 2680, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length2680
Processes
+
ProcessAmount
Process 38 (googleupdate.exe, PID: 2496)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b07d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0400, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0280, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0xa
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x5c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880046b0388, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff880046b0408, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0030, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046b0120, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3de8b0, Length_ptr = 0xa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff880046b0380, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x8
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x793558, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x7
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x793578, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x6
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x793598, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7935e0, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001f296d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f296d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001edb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edb060, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27d148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b04b0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a0013ca300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7588a364, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x795250, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b42001
IoAllocateMdlVirtualAddress_ptr = 0x27e028, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b42001
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x27e8b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b42001
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b42001
IoAllocateMdlVirtualAddress_ptr = 0x3def84, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b42001
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x795730, Length_ptr = 0x34, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df3a4, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a0013ca300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0x8e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df44c, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76b64738, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x795970, Length_ptr = 0x34, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86), _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xc8, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xc8, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x794e78, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27dfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5738d8, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x794f00, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7959a0, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7959a0, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\goopdate.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a000beffc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000beffc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7959a0, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\IPHLPAPI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IPHLPAPI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df2ac, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a000be7eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000be7eb0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df2ac, Length_ptr = 0x14, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x795da0, Length_ptr = 0x66, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\WINNSI.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\WINNSI.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffff8a001a0f1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a0f1c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880046b0a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3df64c, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x795da0, Length_ptr = 0x6a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Program Files (x86)\Google\Update\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e8c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e860, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessret_val_out = 0xfffffa80030b0060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
PsGetCurrentProcessIdret_val_unk_out = 0x9c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #340 (length: 19, amount: 1, processes: 1)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 40 (googlecrashhandler64.exe, PID: 2456)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1aefa8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x322900, Length_ptr = 0x64, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x998
PsGetCurrentProcessret_val_out = 0xfffffa800309b060
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x998
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x998
Execution Path #341 (length: 121, amount: 1, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65b00
_snwprintf_Count = 0x52, _Format = %S, _Dest_out = Ultra3, ret_val_out = 6
_snwprintf_Count = 0x52, _Format = %S, _Dest_out = Ultra3, ret_val_out = 6
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
Execution Path #342 (length: 2, amount: 30, processes: 1)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 2 (System, PID: 4)30
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65b00
Execution Path #343 (length: 73, amount: 1, processes: 1)
+
InformationValue
Sequence Length73
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160f510, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #344 (length: 263, amount: 1, processes: 1)
+
InformationValue
Sequence Length263
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160c320, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1613100, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f183b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #345 (length: 127, amount: 1, processes: 1)
+
InformationValue
Sequence Length127
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1621ff0, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #346 (length: 48, amount: 1, processes: 1)
+
InformationValue
Sequence Length48
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160c7d0, Length_ptr = 0xe6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #347 (length: 373, amount: 1, processes: 1)
+
InformationValue
Sequence Length373
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f437d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1614180, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a7930, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #348 (length: 185, amount: 1, processes: 1)
+
InformationValue
Sequence Length185
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144f720, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1623030, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #350 (length: 121, amount: 1, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144fb20, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #351 (length: 309, amount: 1, processes: 1)
+
InformationValue
Sequence Length309
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x162eed0, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1618980, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a81f0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa97d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #352 (length: 25, amount: 1, processes: 1)
+
InformationValue
Sequence Length25
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
Execution Path #354 (length: 256, amount: 2, processes: 1)
+
InformationValue
Sequence Length256
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d040, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x162f7c0, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #355 (length: 180, amount: 3, processes: 1)
+
InformationValue
Sequence Length180
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1619280, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #356 (length: 380, amount: 1, processes: 1)
+
InformationValue
Sequence Length380
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d220, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d4f0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1660530, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #357 (length: 98, amount: 1, processes: 1)
+
InformationValue
Sequence Length98
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1610930, Length_ptr = 0xfc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #359 (length: 361, amount: 1, processes: 1)
+
InformationValue
Sequence Length361
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d6d0, Length_ptr = 0xe6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1661a30, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #360 (length: 224, amount: 1, processes: 1)
+
InformationValue
Sequence Length224
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d8b0, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1662030, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #362 (length: 144, amount: 1, processes: 1)
+
InformationValue
Sequence Length144
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1632470, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #363 (length: 38, amount: 1, processes: 1)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144fd20, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #365 (length: 149, amount: 1, processes: 1)
+
InformationValue
Sequence Length149
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1663170, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #367 (length: 234, amount: 1, processes: 1)
+
InformationValue
Sequence Length234
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x13c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001559950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001559950, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8003102090, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003102090, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaeec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaeec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaef58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaf3d0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7feff2a5830, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8002c21ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c21ea0, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a114d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a114d0, ret_val_ptr_out = 0xe
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xcaec98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3611c0, Length_ptr = 0x92, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat, _String2 = $NtUninstallQ923283$, _MaxCount = 0x39, ret_val_out = 73
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64\v4.0.30319, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64\v4.0.30319, _String2 = $NtUninstallQ923283$, _MaxCount = 0x23, ret_val_out = 73
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET\Framework64, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET\Framework64, _String2 = $NtUninstallQ923283$, _MaxCount = 0x18, ret_val_out = 73
Execution Path #368 (length: 409, amount: 1, processes: 1)
+
InformationValue
Sequence Length409
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows\Microsoft.NET, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = Microsoft.NET, _String2 = $NtUninstallQ923283$, _MaxCount = 0xc, ret_val_out = 73
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
_wcsnicmp_String1 = Windows, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = , _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = -36
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446bd70, Object_out = 0xfffffa800327b320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327b320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaeb08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf188, Length_ptr = 0x56, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ExGetPreviousModeret_val_unk_out = 0xfffffa800328b701
ProbeForReadAddress_ptr = 0xcaebd8, Length_ptr = 0x4, Alignment = 0x1
ProbeForReadAddress_ptr = 0xcaed18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaed18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf418, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #370 (length: 428, amount: 1, processes: 1)
+
InformationValue
Sequence Length428
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #373 (length: 315, amount: 1, processes: 1)
+
InformationValue
Sequence Length315
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.OracleClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Client, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Client, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xb9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xba, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xbb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.SqlXml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xbc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.SqlXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xbd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Deployment, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xbe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Deployment, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xbf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Device, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.AccountManagement, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.Protocols, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xc9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xca, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xcb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xcc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Dynamic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xcd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.EnterpriseServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xce, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #375 (length: 448, amount: 1, processes: 1)
+
InformationValue
Sequence Length448
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Caching, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Remoting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Remoting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xea, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xeb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xec, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization.Formatters.Soap, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xed, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization.Formatters.Soap, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xee, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xef, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Security, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Channels, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Discovery, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Internals, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.ServiceMoniker40, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xf9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Web, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xfa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xfb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceProcess, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xfc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceProcess, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xfd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Speech, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xfe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Speech, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xff, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Transactions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x100, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Transactions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x101, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x102, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x103, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Abstractions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x104, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Abstractions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x105, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.ApplicationServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x106, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DataVisualization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x107, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DataVisualization.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x108, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DynamicData, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x109, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DynamicData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DynamicData.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.DynamicData.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x110, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Extensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x111, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Extensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x112, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #378 (length: 197, amount: 2, processes: 1)
+
InformationValue
Sequence Length197
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x34b850, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33b270, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #379 (length: 213, amount: 1, processes: 1)
+
InformationValue
Sequence Length213
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1686530, Length_ptr = 0x80, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32f3d0, Length_ptr = 0x72, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #383 (length: 58, amount: 1, processes: 1)
+
InformationValue
Sequence Length58
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33bcf0, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #385 (length: 136, amount: 1, processes: 1)
+
InformationValue
Sequence Length136
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33beb0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #386 (length: 344, amount: 1, processes: 1)
+
InformationValue
Sequence Length344
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33c770, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00135c401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33c930, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33caf0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
Execution Path #388 (length: 44, amount: 1, processes: 1)
+
InformationValue
Sequence Length44
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfd29d0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #391 (length: 5, amount: 1, processes: 1)
+
InformationValue
Sequence Length5
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #393 (length: 11, amount: 5, processes: 2)
+
InformationValue
Sequence Length11
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)4
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x814, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88003ee7a28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee7a20, Object_out = 0xfffffa80030bfea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030bfea0, ret_val_ptr_out = 0x8
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003ee77a0, Object_out = 0xfffffa80030bfea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030bfea0, ret_val_ptr_out = 0x8
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #394 (length: 141, amount: 2, processes: 1)
+
InformationValue
Sequence Length141
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x368530, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x368730, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
Execution Path #397 (length: 29, amount: 1, processes: 1)
+
InformationValue
Sequence Length29
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000774, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002775310, Object_out = 0xfffffa8002b06cd0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002b06cd0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000770, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002775310, Object_out = 0xfffffa8002e47050, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e47050, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #398 (length: 10, amount: 1, processes: 1)
+
InformationValue
Sequence Length10
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000660, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046197e0, Object_out = 0xfffffa800326d870, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800326d870, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #399 (length: 12, amount: 4, processes: 4)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)1
Process 19 (spoolsv.exe, PID: 1020)1
Process 36 (sppsvc.exe, PID: 248)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8003145900
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0xfffffa8002865602, SpinLock_unk_out = 0xfffffa8001c3b260
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #402 (length: 498, amount: 1, processes: 1)
+
InformationValue
Sequence Length498
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcaac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bcaac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcbac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bcbac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bccac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bccac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcdac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bcdac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcead0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bcead0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bcfad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bcfad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd0ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd0ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd1ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd1ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd2ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd2ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd3ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd3ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd4ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd4ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd5ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd5ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd6ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd6ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd7ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd7ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd8ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd8ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bd9ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bd9ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
Execution Path #512 (length: 1124, amount: 1, processes: 1)
+
InformationValue
Sequence Length1124
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b0090, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004257d00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004257d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004258d00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004258d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004259d00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004259d00, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800425ad00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800425ad00, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef4b60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007ef4b60, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1dac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f1dac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1eac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f1eac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f1fac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f1fac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f20ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f20ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f21ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f21ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f22ad0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #403 (length: 185, amount: 1, processes: 1)
+
InformationValue
Sequence Length185
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x396980, Length_ptr = 0x10e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x369f30, Length_ptr = 0xee, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #405 (length: 35, amount: 1, processes: 1)
+
InformationValue
Sequence Length35
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
Execution Path #406 (length: 99, amount: 1, processes: 1)
+
InformationValue
Sequence Length99
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x356eb0, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #409 (length: 174, amount: 1, processes: 1)
+
InformationValue
Sequence Length174
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x154b2a0, Length_ptr = 0x138, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #410 (length: 224, amount: 1, processes: 1)
+
InformationValue
Sequence Length224
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x384590, Length_ptr = 0x134, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf67a40, Length_ptr = 0x14a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #411 (length: 134, amount: 2, processes: 1)
+
InformationValue
Sequence Length134
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x153e270, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #412 (length: 260, amount: 1, processes: 1)
+
InformationValue
Sequence Length260
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155faa0, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x36a330, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cebbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #413 (length: 42, amount: 1, processes: 1)
+
InformationValue
Sequence Length42
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf73c20, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #414 (length: 121, amount: 1, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #415 (length: 439, amount: 1, processes: 1)
+
InformationValue
Sequence Length439
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1681670, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf73e00, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cedbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1560a60, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf73fe0, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #416 (length: 221, amount: 1, processes: 1)
+
InformationValue
Sequence Length221
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf6cc90, Length_ptr = 0x120, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #417 (length: 133, amount: 1, processes: 1)
+
InformationValue
Sequence Length133
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x384810, Length_ptr = 0x128, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #418 (length: 105, amount: 2, processes: 1)
+
InformationValue
Sequence Length105
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x384a90, Length_ptr = 0x12e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #419 (length: 119, amount: 1, processes: 1)
+
InformationValue
Sequence Length119
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x384d10, Length_ptr = 0x12a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #420 (length: 296, amount: 1, processes: 1)
+
InformationValue
Sequence Length296
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3973a0, Length_ptr = 0x108, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15553c0, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #421 (length: 32, amount: 1, processes: 1)
+
InformationValue
Sequence Length32
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #423 (length: 143, amount: 3, processes: 1)
+
InformationValue
Sequence Length143
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)3
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658320, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdcbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdcbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #424 (length: 121, amount: 1, processes: 1)
+
InformationValue
Sequence Length121
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16584e0, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #425 (length: 425, amount: 1, processes: 1)
+
InformationValue
Sequence Length425
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16586a0, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658860, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1003140, Length_ptr = 0x96, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658a20, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #426 (length: 313, amount: 1, processes: 1)
+
InformationValue
Sequence Length313
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658be0, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658da0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1658f60, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
Execution Path #427 (length: 186, amount: 1, processes: 1)
+
InformationValue
Sequence Length186
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1659120, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #428 (length: 411, amount: 1, processes: 1)
+
InformationValue
Sequence Length411
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f4e30, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1001d20, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f5030, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf750c0, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #429 (length: 345, amount: 1, processes: 1)
+
InformationValue
Sequence Length345
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f0220, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f5230, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
Execution Path #430 (length: 220, amount: 1, processes: 1)
+
InformationValue
Sequence Length220
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f5430, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #431 (length: 193, amount: 1, processes: 1)
+
InformationValue
Sequence Length193
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d44b0, Length_ptr = 0xc4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1659740, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #433 (length: 169, amount: 1, processes: 1)
+
InformationValue
Sequence Length169
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f5730, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #434 (length: 312, amount: 1, processes: 1)
+
InformationValue
Sequence Length312
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d5350, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cda301, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f5a30, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #435 (length: 208, amount: 1, processes: 1)
+
InformationValue
Sequence Length208
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ed8b0, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1503a60, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
Execution Path #437 (length: 180, amount: 1, processes: 1)
+
InformationValue
Sequence Length180
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef010, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #440 (length: 181, amount: 1, processes: 1)
+
InformationValue
Sequence Length181
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e1d80, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e2100, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #442 (length: 178, amount: 2, processes: 1)
+
InformationValue
Sequence Length178
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1608da0, Length_ptr = 0x9e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #443 (length: 302, amount: 1, processes: 1)
+
InformationValue
Sequence Length302
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6230, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160d440, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #444 (length: 191, amount: 1, processes: 1)
+
InformationValue
Sequence Length191
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e2b80, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15045a0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #446 (length: 213, amount: 1, processes: 1)
+
InformationValue
Sequence Length213
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160dc80, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6430, Length_ptr = 0xf6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Execution Path #448 (length: 446, amount: 1, processes: 1)
+
InformationValue
Sequence Length446
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e31a0, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14fa380, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e3360, Length_ptr = 0xd6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14fa850, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #450 (length: 1663, amount: 1, processes: 1)
+
InformationValue
Sequence Length1663
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1038cb0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cf1201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x10397f0, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6630, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1044120, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1048fb0, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x10380f0, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6830, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf89580, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #454 (length: 457, amount: 1, processes: 1)
+
InformationValue
Sequence Length457
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1049af0, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf993e0, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf99ac0, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6e30, Length_ptr = 0xee, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #455 (length: 431, amount: 1, processes: 1)
+
InformationValue
Sequence Length431
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfa2e00, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x397940, Length_ptr = 0x112, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1049fa0, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #456 (length: 244, amount: 1, processes: 1)
+
InformationValue
Sequence Length244
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf94620, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104a270, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #458 (length: 267, amount: 1, processes: 1)
+
InformationValue
Sequence Length267
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfa3d00, Length_ptr = 0xb0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfae9f0, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #459 (length: 319, amount: 1, processes: 1)
+
InformationValue
Sequence Length319
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f7230, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e450, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1620710, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #460 (length: 116, amount: 1, processes: 1)
+
InformationValue
Sequence Length116
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104a810, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #462 (length: 51, amount: 1, processes: 1)
+
InformationValue
Sequence Length51
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #463 (length: 142, amount: 2, processes: 1)
+
InformationValue
Sequence Length142
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf94b60, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #464 (length: 149, amount: 1, processes: 1)
+
InformationValue
Sequence Length149
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1572030, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
Execution Path #466 (length: 266, amount: 1, processes: 1)
+
InformationValue
Sequence Length266
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf950a0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ce2201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1574ff0, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #516 (length: 12, amount: 1, processes: 1)
+
InformationValue
Sequence Length12
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #467 (length: 577, amount: 1, processes: 1)
+
InformationValue
Sequence Length577
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1576330, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x157fe30, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1582d90, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x157ffd0, Length_ptr = 0xc6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #468 (length: 172, amount: 1, processes: 1)
+
InformationValue
Sequence Length172
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1580da0, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #469 (length: 239, amount: 1, processes: 1)
+
InformationValue
Sequence Length239
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1572b70, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1572e40, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #471 (length: 146, amount: 1, processes: 1)
+
InformationValue
Sequence Length146
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1585790, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
Execution Path #475 (length: 141, amount: 1, processes: 1)
+
InformationValue
Sequence Length141
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1587a10, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #476 (length: 124, amount: 1, processes: 1)
+
InformationValue
Sequence Length124
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f7c30, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #477 (length: 179, amount: 1, processes: 1)
+
InformationValue
Sequence Length179
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15c5e70, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
Execution Path #481 (length: 81, amount: 1, processes: 1)
+
InformationValue
Sequence Length81
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14458b0, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cefbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf13b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf13b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Execution Path #483 (length: 82, amount: 1, processes: 1)
+
InformationValue
Sequence Length82
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1449330, Length_ptr = 0xb6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #486 (length: 85, amount: 2, processes: 1)
+
InformationValue
Sequence Length85
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd27d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd27d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #487 (length: 402, amount: 1, processes: 1)
+
InformationValue
Sequence Length402
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148a780, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x145e470, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144beb0, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #488 (length: 233, amount: 1, processes: 1)
+
InformationValue
Sequence Length233
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x145e920, Length_ptr = 0xe4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce23b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1493720, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001228010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00169a301, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #489 (length: 139, amount: 1, processes: 1)
+
InformationValue
Sequence Length139
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148b620, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001efa401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #490 (length: 188, amount: 1, processes: 1)
+
InformationValue
Sequence Length188
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1441930, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f8830, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #492 (length: 181, amount: 1, processes: 1)
+
InformationValue
Sequence Length181
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148c320, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f8a30, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #494 (length: 152, amount: 1, processes: 1)
+
InformationValue
Sequence Length152
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148c660, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cef7d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #495 (length: 209, amount: 1, processes: 1)
+
InformationValue
Sequence Length209
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x148cc10, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f8c30, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #496 (length: 251, amount: 1, processes: 1)
+
InformationValue
Sequence Length251
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1496ea0, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8540, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8540, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4510, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #497 (length: 222, amount: 1, processes: 1)
+
InformationValue
Sequence Length222
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1441cb0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14bfe80, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #498 (length: 150, amount: 2, processes: 1)
+
InformationValue
Sequence Length150
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x145f370, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #499 (length: 188, amount: 2, processes: 1)
+
InformationValue
Sequence Length188
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c02a0, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #500 (length: 180, amount: 1, processes: 1)
+
InformationValue
Sequence Length180
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1499f60, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0015598f0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
Execution Path #502 (length: 400, amount: 1, processes: 1)
+
InformationValue
Sequence Length400
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x145fa00, Length_ptr = 0xe6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16b0350, Length_ptr = 0xae, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf3bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x145fbe0, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f43640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #503 (length: 184, amount: 1, processes: 1)
+
InformationValue
Sequence Length184
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16b0950, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf37d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Execution Path #506 (length: 268, amount: 1, processes: 1)
+
InformationValue
Sequence Length268
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c2f50, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf33b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cf33b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4710, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd43b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #507 (length: 42, amount: 1, processes: 1)
+
InformationValue
Sequence Length42
Processes
+
ProcessAmount
Process 14 (svchost.exe, PID: 780)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xbfed50, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d9f80, Length_ptr = 0x1e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = , _String2 = Windows, _MaxCount = 0x7, ret_val_out = 58849
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
Execution Path #508 (length: 60, amount: 1, processes: 1)
+
InformationValue
Sequence Length60
Processes
+
ProcessAmount
Process 14 (svchost.exe, PID: 780)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x644, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800256eb20, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #509 (length: 133, amount: 1, processes: 1)
+
InformationValue
Sequence Length133
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x158ab90, Length_ptr = 0x9e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaf138, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf548, Length_ptr = 0x96, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #510 (length: 10, amount: 2, processes: 2)
+
InformationValue
Sequence Length10
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 13 (svchost.exe, PID: 684)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xd2e9f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef8287a70, Length_ptr = 0x20, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
ExGetPreviousModeret_val_unk_out = 0xfffffa8002ee5001
ProbeForReadAddress_ptr = 0xd2eac8, Length_ptr = 0x4, Alignment = 0x1
PsGetCurrentProcessIdret_val_unk_out = 0x35c
ObReferenceObjectByHandleHandle_unk = 0x6d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880023049d0, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #511 (length: 413, amount: 1, processes: 1)
+
InformationValue
Sequence Length413
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xd2d4c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9d870, Length_ptr = 0x70, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\netip6.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US\netip6.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x28, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f3a500, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f3a500, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #513 (length: 210, amount: 1, processes: 1)
+
InformationValue
Sequence Length210
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f29ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f29ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2aad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f2aad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2bad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f2bad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2cad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f2cad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f2db60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f2db60, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #514 (length: 586, amount: 1, processes: 1)
+
InformationValue
Sequence Length586
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #515 (length: 105, amount: 1, processes: 1)
+
InformationValue
Sequence Length105
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f31ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f31ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f32ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f32ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
Execution Path #565 (length: 563, amount: 1, processes: 1)
+
InformationValue
Sequence Length563
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f33ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f33ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f34ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f34ac0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f35ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f35ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f36ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f36ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f37ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f37ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f38ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f38ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f39ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f39ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3aad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3aad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3bad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3bad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3cad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3cad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3dad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3dad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3ead0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3ead0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3fad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3fad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f50ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f50ad0, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b0100, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a00144eea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00144eea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5dd00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f5dd00, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5ed00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f5ed00, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5fd00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f5fd00, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ed00, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f60d00
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f60d00, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc8
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f61b60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f61b60, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
Execution Path #517 (length: 114, amount: 1, processes: 1)
+
InformationValue
Sequence Length114
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x13c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001edcc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001edcc50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8003102090, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003102090, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaef68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaef68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x128, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaeff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a500, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaf470, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7feff2a5830, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffffa8002c21ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c21ea0, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #518 (length: 1089, amount: 1, processes: 1)
+
InformationValue
Sequence Length1089
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x140, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a114d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a114d0, ret_val_ptr_out = 0x9
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaebd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf258, Length_ptr = 0x56, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ExGetPreviousModeret_val_unk_out = 0xfffffa800328b701
ProbeForReadAddress_ptr = 0xcaeca8, Length_ptr = 0x4, Alignment = 0x1
ProbeForReadAddress_ptr = 0xcaede8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
ProbeForReadAddress_ptr = 0xcaede8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef5eed0c0, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaf088, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf4e8, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x148, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Accessibility, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AspNetMMCExt, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = AuditPolicyGPManagedStubs.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -20
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = BDATunePIA, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -19
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/ComSvcConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/dfsvc.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/MSBuild.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/SMSvcHost.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = C:/Windows/Microsoft.NET/Framework64/v4.0.30319/WsatConfig.exe, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ComSvcConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = CustomMarshalers, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = dfsvc, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 15
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehCIR, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehshell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = EventViewer, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = loadmxf, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 23
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcepg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x20, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MCESidebarCtrl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x21, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcglidhostobj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x22, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcplayerinterop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x23, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstore, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x24, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcstoredb, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x25, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mcupdate, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x26, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Mcx2Dvcs, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x27, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft-Windows-HomeGroupDiagnostic.NetListMgr.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x28, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Activities.Build, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x29, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.Framework, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ApplicationId.RuleWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Conversion.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Engine, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Framework, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x30, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x31, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Tasks.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x32, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x33, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Build.Utilities.v3.5, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x34, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.CSharp, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x35, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.AdmTmplEditor, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x36, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Interop, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x37, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.GroupPolicy.Reporting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x38, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Ink, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x39, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Internal.Tasks.Dataflow, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.ManagementConsole, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Bml, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTv.Hosting, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x40, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.iTV.Media, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x41, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.ITVVM, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x42, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Mheg, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x43, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Playback, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x44, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Shell, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x45, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.Sports, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x46, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #523 (length: 245, amount: 1, processes: 1)
+
InformationValue
Sequence Length245
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15ce310, Length_ptr = 0x80, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32f150, Length_ptr = 0x72, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #589 (length: 335, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length335
Processes
+
ProcessAmount
Process 39 (googlecrashhandler.exe, PID: 2460)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d7d0, Object_out = 0xfffff8a003e4c7f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e4c7f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d400, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d280, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0xa
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0x50, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x20000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20040, Length_ptr = 0xe, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59dd2, Length_ptr = 0x86, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59548, Length_ptr = 0x7e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b593c8, Length_ptr = 0x84, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x58, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800234d388, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800234d408, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = en-US, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d030, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800234d120, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ee990, Length_ptr = 0xa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800234d380, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a740, Length_ptr = 0xa0, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x8
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e4f80, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a9ce, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b597f4, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x7
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e4f80, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5aa48, Length_ptr = 0x56, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x6
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e4b80, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5a960, Length_ptr = 0x62, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b594ec, Length_ptr = 0x2a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e4b80, Length_ptr = 0x2e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b59244, Length_ptr = 0x3e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001820580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001820580, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27cd08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234d4b0, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x68, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoAllocateMdlVirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002a7fe70
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002a7fe70, AccessMode_unk = 0xfffffa8002a7fe01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002a7fe70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002a7fe70, MemoryDescriptorList_unk_out = 0xfffffa8002a7fe70
IoFreeMdlMdl_unk = 0xfffffa8002a7fe70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x3ef69c, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
ProbeForReadAddress_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a3948, Length_ptr = 0x78, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7efe1440, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e5b88, Length_ptr = 0x34, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27db78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x74dd1670, Length_ptr = 0x7c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800234da80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #541 (length: 27, amount: 1, processes: 1)
+
InformationValue
Sequence Length27
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #525 (length: 119, amount: 1, processes: 1)
+
InformationValue
Sequence Length119
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa8002e65600
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
Execution Path #528 (length: 149, amount: 1, processes: 1)
+
InformationValue
Sequence Length149
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x158b7f0, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #529 (length: 61, amount: 1, processes: 1)
+
InformationValue
Sequence Length61
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bc8e0, Length_ptr = 0xcc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #533 (length: 334, amount: 1, processes: 1)
+
InformationValue
Sequence Length334
Processes
+
ProcessAmount
Process 20 (svchost.exe, PID: 1040)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x184df08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a7a1d0, Length_ptr = 0x8a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
_wcsnicmp_String1 = Windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = system32\WDI\BootPerformanceDiagnostics_SystemData.bin, _String2 = $NtUninstallQ923283$, _MaxCount = 0x35, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
_wcsnicmp_String1 = Windows\System32\wdi, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\wdi, _String2 = $NtUninstallQ923283$, _MaxCount = 0xb, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f41c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001f41c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a95d70, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x410
Execution Path #603 (length: 39, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length39
Processes
+
ProcessAmount
Process 20 (svchost.exe, PID: 1040)1
Sequence
+
SymbolParameters
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x7c, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88002a96a28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a96a20, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x2
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x410
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002a967a0, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x410
PsGetCurrentProcessret_val_out = 0xfffffa8002bfe340
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #534 (length: 56, amount: 1, processes: 1)
+
InformationValue
Sequence Length56
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14e2bf0, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
Execution Path #536 (length: 51, amount: 1, processes: 1)
+
InformationValue
Sequence Length51
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x337d10, Length_ptr = 0x130, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #537 (length: 245, amount: 1, processes: 1)
+
InformationValue
Sequence Length245
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14cb930, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #538 (length: 31, amount: 1, processes: 1)
+
InformationValue
Sequence Length31
Processes
+
ProcessAmount
Process 31 (mscorsvw.exe, PID: 2128)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002743470
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002eaaa20
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002743470
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002eaaa20
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002743470
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002eaaa20
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002eaaa02, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #539 (length: 230, amount: 1, processes: 1)
+
InformationValue
Sequence Length230
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4710, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4910, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #599 (length: 180, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length180
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa8002f5a600
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619590, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000438, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619640, Object_out = 0xfffff8a001f3ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f3ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619640, Object_out = 0xfffff8a00115ffa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00115ffa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ExGetPreviousModeret_val_unk_out = 0xfffffa8002f5a600
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619470, Object_out = 0xfffff8a00115ffa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00115ffa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000438, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001f3ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f3ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046195f0, Object_out = 0xfffffa80030b1360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030b1360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880046192a0, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004619520, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #543 (length: 137, amount: 2, processes: 1)
+
InformationValue
Sequence Length137
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e42920, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e42920, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001469c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003289190
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003289190, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003289190
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003289190, MemoryDescriptorList_unk_out = 0xfffffa8003289190
IoFreeMdlMdl_unk = 0xfffffa8003289190
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001469c00, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003289190
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003289190, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003289190
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003289190, MemoryDescriptorList_unk_out = 0xfffffa8003289190
IoFreeMdlMdl_unk = 0xfffffa8003289190
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e425b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e425b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047886d0, Object_out = 0xfffffa8002e42050, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e42050, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Execution Path #544 (length: 123, amount: 1, processes: 1)
+
InformationValue
Sequence Length123
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4d10, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff8000047c, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff8000047c, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff8000047c, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff8000047c, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #548 (length: 17, amount: 1, processes: 1)
+
InformationValue
Sequence Length17
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002a682b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a682b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb23a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb23a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #550 (length: 1011, amount: 1, processes: 1)
+
InformationValue
Sequence Length1011
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f308, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f058, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd72d40, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ExGetPreviousModeret_val_unk_out = 0xfffffa8002f4fb01
ProbeForReadAddress_ptr = 0x132f128, Length_ptr = 0x4, Alignment = 0x1
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd72db0, Length_ptr = 0x6a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd72e20, Length_ptr = 0x60, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f2a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f108, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd73020, Length_ptr = 0x4a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132efc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ee28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd73070, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f2f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f158, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd72ee0, Length_ptr = 0x58, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f210, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0740
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0740, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0740
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0740, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ee8210
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007ee8210, MemoryDescriptorList_unk = 0xfffffa80025d0740
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0740, MemoryDescriptorList_unk_out = 0xfffffa80025d0740
IoFreeMdlMdl_unk = 0xfffffa80025d0740
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebf8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb3540, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb3540, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebf8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ef38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e898, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132e6f8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ebe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132ea48, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eff8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f040, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef8170
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007ef8170, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007ef9170
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007ef9170, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efa170
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007efa170, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f170, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efb170
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007efb170, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efc180
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007efc180, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efd180
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007efd180, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #549 (length: 101, amount: 1, processes: 1)
+
InformationValue
Sequence Length101
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c5310, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000430, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000430, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000430, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000430, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #607 (length: 31, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length31
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000440, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880027751e0, Object_out = 0xfffffa8002eb4620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #553 (length: 237, amount: 1, processes: 1)
+
InformationValue
Sequence Length237
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0c0d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f0c0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
IoFreeMdlMdl_unk = 0xfffffa80025d0810
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0d0d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f0d0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
IoFreeMdlMdl_unk = 0xfffffa80025d0810
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0e0d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f0e0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
IoFreeMdlMdl_unk = 0xfffffa80025d0810
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc7
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0810
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0810, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f0f0d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f0f0d0, MemoryDescriptorList_unk = 0xfffffa80025d0810
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0810, MemoryDescriptorList_unk_out = 0xfffffa80025d0810
IoFreeMdlMdl_unk = 0xfffffa80025d0810
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc6
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e43a00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e43a00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #555 (length: 397, amount: 1, processes: 1)
+
InformationValue
Sequence Length397
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x166d2c0, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000458, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3a3f00, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000458, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x166d4e0, Length_ptr = 0x106, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000458, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000458, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000458, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #563 (length: 17, amount: 1, processes: 1)
+
InformationValue
Sequence Length17
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #564 (length: 163, amount: 1, processes: 1)
+
InformationValue
Sequence Length163
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x166de70, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800006dc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800006dc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800006dc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800006dc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c5b10, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #567 (length: 935, amount: 1, processes: 1)
+
InformationValue
Sequence Length935
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5800, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7cac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f7cac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7dac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f7dac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7eac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f7eac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f7fac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f7fac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f90ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f90ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f91ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f91ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f92ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f92ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f93ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f93ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f94ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f94ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f95ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f95ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f96ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f96ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f97ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f97ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f98ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f98ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f99ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f99ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9aad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f9aad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9bad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f9bad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #569 (length: 512, amount: 1, processes: 1)
+
InformationValue
Sequence Length512
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc4ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc4ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc5ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc5ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc6ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc6ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc7ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc7ac0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc8ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc8ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fc9ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fc9ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcaad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fcaad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcbad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fcbad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fccad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fccad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcdad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fcdad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcead0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fcead0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fcfad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fcfad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd0ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fd0ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd1ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fd1ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd2ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fd2ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
Kernel Graph 9
No Kernel Graph Available
Code Block #12 ( EP #578, #139, #119, #142, #598, #524, #590, #592, #594, #608)
+
InformationValue
TriggerKiRetireDpcList+0x26a
Start Address0xfffffa8001bc4b12
Execution Path #578 (length: 10, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length10
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80031a6e40
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa800311b170
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa800311b102, SpinLock_unk_out = 0xfffffa8001c3a658
Execution Path #139 (length: 17, amount: 4, processes: 4)
+
InformationValue
Sequence Length17
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)1
Process 11 (svchost.exe, PID: 564)1
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa800303b760
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80018b09d0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80018b0902, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #119 (length: 7, amount: 2, processes: 2)
+
InformationValue
Sequence Length7
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8003147100
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #142 (length: 13, amount: 2, processes: 2)
+
InformationValue
Sequence Length13
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Process 37 (googleupdate.exe, PID: 1000)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030fac30
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80031fc070
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80031fc002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #598 (length: 6, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x9b8
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #524 (length: 3, amount: 1, processes: 1)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 25 (svchost.exe, PID: 1692)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x488
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #590 (length: 2, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #592 (length: 189, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length189
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80025a5400
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa80025a5402, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002bace40
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030b76e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80027670e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030b76e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80027670e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030b76e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030b76e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80027670e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80030b76e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80027670e0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002767002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x8f0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80031f2170
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x8f0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x8f0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002732670
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002732670
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3b260, SpinLock_unk_out = 0xfffffa8001c3b260, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3b260, NewIrql_unk = 0x2, SpinLock_unk_out = 0xfffffa8001c3b260
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002778c20
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa80025410d0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002541002, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002743470
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
NdisGetDataBufferret_val_out = 0xfffffa8002fb7380
KeGetCurrentIrqlret_val_unk_out = 0x2
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c3a658, SpinLock_unk_out = 0xfffffa8001c3a658, ret_val_unk_out = 0x2
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c3a658, NewIrql_unk = 0xfffffa8002fb7302, SpinLock_unk_out = 0xfffffa8001c3a658
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x8f0
Execution Path #594 (length: 11, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length11
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Execution Path #608 (length: 6, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 15 (svchost.exe, PID: 836)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x4b4
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x4b4
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
Kernel Graph 10
No Kernel Graph Available
Code Block #14 ( EP #36, #404)
+
InformationValue
Triggerunknown_0xfffffa8001be0000+0x661
Start Address0xfffff80002719480
Execution Path #36 (length: 1, amount: 286, processes: 9)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)267
Process 37 (googleupdate.exe, PID: 1000)2
Process 8 (services.exe, PID: 448)1
Process 11 (svchost.exe, PID: 564)1
Process 15 (svchost.exe, PID: 836)1
Process 16 (svchost.exe, PID: 860)4
Process 18 (svchost.exe, PID: 264)7
Process 20 (svchost.exe, PID: 1040)1
Process 26 (taskeng.exe, PID: 1876)2
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #404 (length: 289, amount: 1, processes: 1)
+
InformationValue
Sequence Length289
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002e9f340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e9f340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd731a0, Length_ptr = 0x80, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132eec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcd73230, Length_ptr = 0x8a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be40d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000be40d0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be50d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000be50d0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be60d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000be60d0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f0d0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000be70d0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000be70d0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
ProbeForReadAddress_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
Kernel Graph 11
No Kernel Graph Available
Code Block #15 ( EP #37)
+
InformationValue
Triggerunknown_0xfffffa8001be0000+0x66d
Start Address0xfffff80002719514
Execution Path #37 (length: 1, amount: 227, processes: 3)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Process 2 (System, PID: 4)225
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
Kernel Graph 12
No Kernel Graph Available
Code Block #16 ( EP #38)
+
InformationValue
Triggerunknown_0xfffffa8001be0000+0x6b5
Start Address0xfffff800027194b0
Execution Path #38 (length: 1, amount: 267, processes: 3)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Process 2 (System, PID: 4)265
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Kernel Graph 13
No Kernel Graph Available
Code Block #17 ( EP #39, #547, #560)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x75e
Start Address0xfffff800026ef420
Execution Path #39 (length: 1, amount: 21, processes: 13)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Process 34 (googleupdate.exe, PID: 2220)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 8 (services.exe, PID: 448)2
Process 41 (googleupdate.exe, PID: 2440)1
Process 11 (svchost.exe, PID: 564)3
Process 13 (svchost.exe, PID: 684)1
Process 14 (svchost.exe, PID: 780)1
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)6
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
Execution Path #547 (length: 53, amount: 1, processes: 1)
+
InformationValue
Sequence Length53
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1c8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa80030a7b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030a7b50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x104, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa800251a510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800251a510, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002eb1e00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb1e00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #560 (length: 573, amount: 1, processes: 1)
+
InformationValue
Sequence Length573
Processes
+
ProcessAmount
Process 15 (svchost.exe, PID: 836)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdbb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa80030c4eb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030c4eb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x540, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x544, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa8002ed4200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ed4200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdbb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdef8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fdd58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fd858, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fd6b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e66980, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 14
No Kernel Graph Available
Code Block #18 ( EP #40)
+
InformationValue
Triggerunknown_0xfffffa8001bde000+0x328
Start Address0xfffff800026d3770
Execution Path #40 (length: 1, amount: 45, processes: 12)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)2
Process 37 (googleupdate.exe, PID: 1000)2
Process 38 (googleupdate.exe, PID: 2496)2
Process 39 (googlecrashhandler.exe, PID: 2460)2
Process 8 (services.exe, PID: 448)4
Process 41 (googleupdate.exe, PID: 2440)2
Process 11 (svchost.exe, PID: 564)5
Process 2 (System, PID: 4)12
Process 14 (svchost.exe, PID: 780)2
Process 13 (svchost.exe, PID: 684)2
Process 16 (svchost.exe, PID: 860)2
Process 18 (svchost.exe, PID: 264)8
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Kernel Graph 15
No Kernel Graph Available
Code Block #19 ( EP #41)
+
InformationValue
Triggerunknown_0xfffffa8001bde000+0x37d
Start Address0xfffff800026d6c60
Execution Path #41 (length: 1, amount: 45, processes: 12)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)2
Process 37 (googleupdate.exe, PID: 1000)2
Process 38 (googleupdate.exe, PID: 2496)2
Process 39 (googlecrashhandler.exe, PID: 2460)2
Process 8 (services.exe, PID: 448)4
Process 41 (googleupdate.exe, PID: 2440)2
Process 11 (svchost.exe, PID: 564)5
Process 2 (System, PID: 4)12
Process 14 (svchost.exe, PID: 780)2
Process 13 (svchost.exe, PID: 684)2
Process 16 (svchost.exe, PID: 860)2
Process 18 (svchost.exe, PID: 264)8
Sequence
+
SymbolParameters
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Kernel Graph 16
No Kernel Graph Available
Code Block #20 ( EP #42, #299, #326, #330, #532)
+
InformationValue
Triggerunknown_0xfffffa8001bc9000+0x742
Start Address0xfffff800029a8150
Execution Path #42 (length: 1, amount: 18, processes: 12)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 8 (services.exe, PID: 448)2
Process 41 (googleupdate.exe, PID: 2440)1
Process 11 (svchost.exe, PID: 564)3
Process 13 (svchost.exe, PID: 684)1
Process 14 (svchost.exe, PID: 780)1
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)4
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219830, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #299 (length: 43, amount: 1, processes: 1)
+
InformationValue
Sequence Length43
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #326 (length: 161, amount: 1, processes: 1)
+
InformationValue
Sequence Length161
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1560b70, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #330 (length: 167, amount: 2, processes: 1)
+
InformationValue
Sequence Length167
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144e720, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #532 (length: 203, amount: 1, processes: 1)
+
InformationValue
Sequence Length203
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bce20, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 17
No Kernel Graph Available
Code Block #21 ( EP #43)
+
InformationValue
Triggerunknown_0xfffffa8001bc9000+0x78d
Start Address0xfffff800026d5e60
Execution Path #43 (length: 1, amount: 18, processes: 12)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Process 8 (services.exe, PID: 448)2
Process 41 (googleupdate.exe, PID: 2440)1
Process 11 (svchost.exe, PID: 564)3
Process 13 (svchost.exe, PID: 684)1
Process 14 (svchost.exe, PID: 780)1
Process 16 (svchost.exe, PID: 860)1
Process 18 (svchost.exe, PID: 264)4
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xf
Kernel Graph 18
No Kernel Graph Available
Code Block #22 ( EP #575, #138, #582, #148, #147, #585, #586, #588, #593, #596, #597, #600, #601, #602, #604, #605, #545, #546)
+
InformationValue
Triggerunknown_0xfffffa8001c02000+0x70
Start Address0xfffff800026cb153
Execution Path #575 (length: 377, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length377
Processes
+
ProcessAmount
Process 8 (services.exe, PID: 448)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xe1d9e0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xe1dd00, Length_ptr = 0x88, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
ProbeForReadAddress_ptr = 0xe1d9e0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778cef00, Length_ptr = 0x2a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1dc58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778cf040, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
ProbeForReadAddress_ptr = 0xe1dc58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xe1dd00, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1d5f0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xe1d800, Length_ptr = 0x56, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003219830, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xf
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a0013e0c70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013e0c70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xe1e1f0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce900, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1de50, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xe1e060, Length_ptr = 0x56, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001ba2810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2810, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xe1d9c0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xe1dbd0, Length_ptr = 0x56, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
_wcsnicmp_String1 = Windows\AppPatch\AppPatch64\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\AppPatch64\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x1e, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x368, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001ba2810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2810, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030e1720, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030e1720, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x320, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80018fe510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80018fe510, ret_val_ptr_out = 0xe
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessret_val_out = 0xfffffa8002bf8b30
strncpy_Source = services.exe, _Count = 0x52, _Dest_out = services.exe, ret_val_out = services.exe
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = services.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x358, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a000d2fdd0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d2fdd0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa80030f7490, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030f7490, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x364, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa8002519060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002519060, ret_val_ptr_out = 0x24
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1553a0, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160ba0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f0b0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1602d0, Length_ptr = 0xa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f0f0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16c970, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f130, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f070, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1f020, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xe1efe0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16d200, Length_ptr = 0xc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x1c0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x35c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003219a80, Object_out = 0xfffffa8002e08a70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e08a70, ret_val_ptr_out = 0xbc
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #138 (length: 9, amount: 3, processes: 3)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 41 (googleupdate.exe, PID: 2440)1
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c3898, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30664, Length_ptr = 0x20, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b5324e, Length_ptr = 0x84, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
Execution Path #582 (length: 857, amount: 2, processes: 2 incomplete)
+
InformationValue
Sequence Length857
Processes
+
ProcessAmount
Process 37 (googleupdate.exe, PID: 1000)1
Process 38 (googleupdate.exe, PID: 2496)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e110, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x38f3d8, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x422550, Length_ptr = 0x64, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f05c, Length_ptr = 0x1c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12ddf8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c3060, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a0004d7840, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0004d7840, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x42186c, Length_ptr = 0x20, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001ed4b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed4b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001eedc50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eedc50, ret_val_ptr_out = 0xd
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f20c, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38eee0, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x423188, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x423188, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38eb40, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e814, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e4e8, Length_ptr = 0x1a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38f20c, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38ee6c, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38eacc, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e7a0, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e7a0, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e474, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e3b4, Length_ptr = 0x8e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x38f378, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x763f6c08, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xac, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x40, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x766d18d0, Length_ptr = 0x84, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x12e940, Length_ptr = 0x42, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
_wcsnicmp_String1 = Windows\SysWOW64\IMM32.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\IMM32.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x11, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffffa80031c5650, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031c5650, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x12e9a0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38e630, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a000bf0b50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf0b50, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessret_val_out = 0xfffffa800251c060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
IoAllocateMdlVirtualAddress_ptr = 0x12e108, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x12e990, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8003138801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x12e098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1c38d8, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
PsGetCurrentProcessIdret_val_unk_out = 0x3e8
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x48, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044faa80, Object_out = 0xfffff8a001e55520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e55520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #148 (length: 15, amount: 1, processes: 1)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x141eab0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x749bf8, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
Execution Path #147 (length: 3253, amount: 1, processes: 1)
+
InformationValue
Sequence Length3253
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00030abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Control, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -18
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a00183c520, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c520, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f54bf0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007f8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffff88002bb8598, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007f8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = #, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -50
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb81c0, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a001ec14e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec14e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff00, Object_ptr_out = 0xfffff88002bb8510, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002bb8640, Object_out = 0xfffff8a000f24060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f24060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #585 (length: 1290, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1290
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5b4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffffa8002519060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002519060, ret_val_ptr_out = 0x1e
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffffa800327ed10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800327ed10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001216060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001216060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165dce8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x165e4c0, Length_ptr = 0x6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd158, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e518, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd158, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cda670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cda670, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b76670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b76670, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f02670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f02670, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001800060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001800060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd2670, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd2670, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a68, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e518, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a68, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e1e060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1e060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f1e530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f1e530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f18430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f18430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a00182a060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182a060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x78, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd2530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001800060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001800060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x3a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cf7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf7530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x64, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001e1e060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1e060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cff530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cff530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0011e3060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0011e3060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ce8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce8530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ced060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ced060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0019d0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019d0060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001cd4530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd4530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001ceb060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ceb060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x30, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0019d6060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019d6060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x34, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5bc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a001d01530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d01530, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e348, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4dd150, Length_ptr = 0x34, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x165e598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d7a60, Length_ptr = 0x34, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x234
PsGetCurrentProcessIdret_val_unk_out = 0x234
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bb8a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #586 (length: 1247, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1247
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xf4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031fb9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031fb9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xf8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311a230, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800311a230, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x100, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003206430, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003206430, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xfc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311c960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800311c960, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x104, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002ff51b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ff51b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xf0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80030b58d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030b58d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003230380, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003230380, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xd8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032083f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80032083f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xd0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032084b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80032084b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003208570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003208570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003226f10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003226f10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003284790, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003284790, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003251fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003251fc0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xb0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xb4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002df66c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002df66c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003145f60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003145f60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xffffffffffffffff, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88004459a50, ret_val_unk_out = 0x0
ZwQueryInformationProcessProcessHandle_unk = 0xffffffff800007b0, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff88004459a58, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
PsLookupProcessByProcessIdProcessId_unk = 0x8ac, Process_unk_out = 0xfffff880044598b8, ret_val_unk_out = 0x0
strncpy_Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
ObfDereferenceObjectObject_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x3f
_stricmp_Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwCloseHandle_unk = 0xffffffff800007b0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044597f0, Object_out = 0xfffffa80031529e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x3f
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x284, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003156920, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003156920, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x280, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800321c6c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800321c6c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x288, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x27c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800313d560, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800313d560, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800313c8d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800313c8d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x208, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80018c5be0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80018c5be0, ret_val_ptr_out = 0x17
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000dbf3c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000dbf3c0, ret_val_ptr_out = 0x24
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031627d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031627d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1f0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003162590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003162590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x194, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800326b310, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800326b310, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x198, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fb4be0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb4be0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x19c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031531e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031531e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1a0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d7d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302d7d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1a4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d850, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302d850, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002547940, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002547940, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302c8b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302c8b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003152120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003152120, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x18c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003163070, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163070, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x180, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800311ace0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800311ace0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x184, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304ae90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800304ae90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x168, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003153bc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003153bc0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x16c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003153c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003153c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x170, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d8e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302d8e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x174, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800302d9a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302d9a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x178, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002e95440, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e95440, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x17c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dd5180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dd5180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fc8070, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fc8070, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80025201e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80025201e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003028ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xdc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028fb0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003028fb0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xcc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028bc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003028bc0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x80, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8003028c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003028c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dd7e60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dd7e60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x9c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x7c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x200, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x70, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dec7d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dec7d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8001ad6e20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001ad6e20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x64, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002f586d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f586d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x68, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80032302c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80032302c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x6c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304cb80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800304cb80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x74, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002dec710, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dec710, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x78, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000f92500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f92500, ret_val_ptr_out = 0xa
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x210, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000f92500, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f92500, ret_val_ptr_out = 0x9
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x11c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000305330, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000305330, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x60, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fbbe60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fbbe60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa80031fc3e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031fc3e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21dc18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffff8a000305330, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000305330, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x34, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002fa0ab0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fa0ab0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x12c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800304cac0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800304cac0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa800319b370, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800319b370, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x30, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004459a80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0xffffffffffffffff, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff88004459a50, ret_val_unk_out = 0x0
ZwQueryInformationProcessProcessHandle_unk = 0xffffffff800007b0, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff88004459a58, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
PsLookupProcessByProcessIdProcessId_unk = 0x8ac, Process_unk_out = 0xfffff880044598b8, ret_val_unk_out = 0x0
strncpy_Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
ObfDereferenceObjectObject_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x24
_stricmp_Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwCloseHandle_unk = 0xffffffff800007b0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044597f0, Object_out = 0xfffffa80031529e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80031529e0, ret_val_ptr_out = 0x24
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #588 (length: 1522, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1522
Processes
+
ProcessAmount
Process 39 (googlecrashhandler.exe, PID: 2460)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbf0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x3ef72c, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7d25b8, Length_ptr = 0x64, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x99c
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef3b0, Length_ptr = 0x1c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
ProbeForReadAddress_ptr = 0x27d8d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x5a30d0, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001ed0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed0060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x27dbe8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoAllocateMdlVirtualAddress_ptr = 0x27e470, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0xfffffa8002f59501, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
IoAllocateMdlVirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002dc8f40
ExGetPreviousModeret_val_unk_out = 0xfffffa8002b99301
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, AccessMode_unk = 0xfffffa8002dc8f01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002dc8f40, MemoryDescriptorList_unk_out = 0xfffffa8002dc8f40
IoFreeMdlMdl_unk = 0xfffffa8002dc8f40
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001f406d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f406d0, ret_val_ptr_out = 0xd
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef234, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7d31f8, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7d31f8, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3eee94, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3eeb68, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ee83c, Length_ptr = 0x1a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f80950, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f80950, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3eee94, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3eee94, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3eeb68, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e1010, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\NETAPI32.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\NETAPI32.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e1010, Length_ptr = 0x7c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\netutils.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\netutils.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\netutils.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x14, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e1010, Length_ptr = 0x78, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\srvcli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\srvcli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\srvcli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x14, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e1010, Length_ptr = 0x78, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\wkscli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x44, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Windows\SysWOW64\wkscli.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\wkscli.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x12, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001287620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287620, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002da7740, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002da7740, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a003eee830, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003eee830, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef1c0, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessIdret_val_unk_out = 0x99c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a000bf0d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf0d60, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ef560, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7e1768, Length_ptr = 0x7a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\VERSION.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
ProbeForReadAddress_ptr = 0x27e480, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x27e420, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x99c
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleCrashHan, _Count = 0x52, _Dest_out = GoogleCrashHan, ret_val_out = GoogleCrashHan
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleCrashHan, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #593 (length: 4265, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length4265
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004322430
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004322430, MemoryDescriptorList_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004323430
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004323430, MemoryDescriptorList_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004324430
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004324430, MemoryDescriptorList_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff430, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004325430
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004325430, MemoryDescriptorList_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff420, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f59580
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f59580, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004326420
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004326420, MemoryDescriptorList_unk = 0xfffffa8002f59580
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f59580, MemoryDescriptorList_unk_out = 0xfffffa8002f59580
IoFreeMdlMdl_unk = 0xfffffa8002f59580
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002c45990, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002c45990, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002b16120, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002b16120, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa80030d8170, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030d8170, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a200, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x230, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffffa8000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800457aa28, ret_val_unk_out = 0x0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0xfffffa80018c24b0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457aa20, Object_out = 0xfffffa8002dee360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dee360, ret_val_ptr_out = 0x2
ZwCloseHandle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800457a7a0, Object_out = 0xfffffa8002dee360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dee360, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a000d2c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d2c060, ret_val_ptr_out = 0x15
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc5
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x35ff290, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f78290
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f78290, MemoryDescriptorList_unk = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec78, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fead8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a69570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35feac8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fefb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fee18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35fe918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x35fe778, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001f05ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x35ff078, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35ff0c0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa800312b570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800312b570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800457aa80, Object_out = 0xfffffa8002a69570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #596 (length: 18839, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length18839
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042827e0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042827e0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042837e0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042837e0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042847e0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042847e0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7e0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042857e0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042857e0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042867f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042867f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042877f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042877f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042887f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042887f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042897f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042897f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428a7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428a7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428b7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428b7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428c7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428c7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428d7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428d7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428e7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428e7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff8800428f7f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff8800428f7f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042907f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042907f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f7f0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042917f0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042917f0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbf
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x170f880, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004292880
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004292880, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f5a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f408, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f5a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f408, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170ef08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170ed68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f668, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x170f6b0, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f268, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f258, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffffa800309afe0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800309afe0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x170f0b8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d58c0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x278, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002b76a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #597 (length: 8224, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length8224
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1ee08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1ec68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1e768, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1e5c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1eab8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1eab8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1e918, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1eec8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1ef10, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e1040
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e1040, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e2040
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e2040, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e3040
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e3040, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f040, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e4040
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e4040, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e5050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e5050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e6050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e6050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e7050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e7050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e8050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e8050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042e9050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042e9050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ea050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042ea050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042eb050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042eb050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ec050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042ec050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ed050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042ed050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ee050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042ee050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff880042ef050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff880042ef050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004300050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004300050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1f148, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1d1efa8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b0170, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004301050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004301050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc4
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1d1f050, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002f7e130
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002f7e130, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88004311050
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88004311050, MemoryDescriptorList_unk = 0xfffffa8002f7e130
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002f7e130, MemoryDescriptorList_unk_out = 0xfffffa8002f7e130
IoFreeMdlMdl_unk = 0xfffffa8002f7e130
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc3
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x620, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004747a80, Object_out = 0xfffffa8002bd16a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002bd16a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1d1f000, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d1f070, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #600 (length: 1336, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1336
Processes
+
ProcessAmount
Process 14 (svchost.exe, PID: 780)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xbfd338, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef8286ac0, Length_ptr = 0x1c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x408, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001b6fc70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6fc70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4a8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eed420, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eed420, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4a4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x3e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa800326b310, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800326b310, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfd748, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd7a0, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfd8c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
ProbeForReadAddress_ptr = 0xbfd728, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x34c310, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfd8c8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
ProbeForReadAddress_ptr = 0xbfd728, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x34c310, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfdab0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20f7110, Length_ptr = 0x5c, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xbfddb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
ProbeForReadAddress_ptr = 0xbfdc18, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef713ff70, Length_ptr = 0x40, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfda60, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20f6240, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\dot3api.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\dot3api.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfdbc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\dot3api.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\dot3api.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002eda801
IoAllocateMdlVirtualAddress_ptr = 0xbfd810, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa8002eda801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa8002eda801
IoAllocateMdlVirtualAddress_ptr = 0xbfd800, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa8002eda801
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x3e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa80030b1240, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030b1240, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002968f30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002968f30, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002b06c30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002b06c30, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xbfda60, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x20f6258, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\wlanhlp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\wlanhlp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfdbc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\wlanhlp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\wlanhlp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\Wlanapi.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\Wlanapi.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\Wlanapi.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\Wlanapi.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfce80, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd110, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfce28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\wlanutil.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\wlanutil.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfcfe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\wlanutil.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\wlanutil.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd700, Length_ptr = 0x10, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x40, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\OneX.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\OneX.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x10, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd5d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x40, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\OneX.DLL, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\OneX.DLL, _String2 = $NtUninstallQ923283$, _MaxCount = 0x10, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfce80, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd110, Length_ptr = 0x18, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfce28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\eappprxy.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\eappprxy.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfcfe8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x48, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\eappprxy.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\eappprxy.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x14, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x460, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x30c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x478, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800256fa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xbfd470, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xbfd700, Length_ptr = 0x16, Alignment = 0x2
ProbeForReadAddress_ptr = 0xbfd418, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3d0220, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
PsGetCurrentProcessret_val_out = 0xfffffa8002ea6060
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x30c
_wcsnicmp_String1 = Windows\System32\eappcfg.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\eappcfg.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #601 (length: 32036, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length32036
Processes
+
ProcessAmount
Process 16 (svchost.exe, PID: 860)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eed420, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eed420, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa800302b360, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800302b360, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xd2e638, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
ProbeForReadAddress_ptr = 0xd2e498, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xd2e9d0, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xd2ea68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef8288c50, Length_ptr = 0x6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xd2ea68, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fef8286ac0, Length_ptr = 0x1c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x26, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\INF\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = INF\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2, ret_val_out = 69
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d3e0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9d870, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2a, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32, _String2 = $NtUninstallQ923283$, _MaxCount = 0x7, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = \, _String2 = $NtUninstallQ923283$, _MaxCount = 0xffffffff, ret_val_out = 56
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001ed6680, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0xfffff8a001ed6680, Length = 0x1c, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
_wcsicmp_Str1 = System32, _Str2 = $NtUninstallQ923283$, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bf00
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88002303c80, Object_out = 0xfffffa8002eb6ad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb6ad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x52, _Dest_out = System, ret_val_out = System
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = System, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x54, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d658, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x3e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\INF\netnwifi.PNF, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = INF\netnwifi.PNF, _String2 = $NtUninstallQ923283$, _MaxCount = 0xf, ret_val_out = 69
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x26, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\INF\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = INF\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2, ret_val_out = 69
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\inf\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d3e0, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9d870, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US\netnwifi.inf_loc, _String2 = $NtUninstallQ923283$, _MaxCount = 0x2a, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d598, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x54, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = System32\DriverStore\en-US\, _String2 = $NtUninstallQ923283$, _MaxCount = 0x19, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
_wcsnicmp_String1 = Windows\System32\DriverStore\en-US\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0xd2d658, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d9ee50, Length_ptr = 0x3e, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
_wcsnicmp_String1 = Windows\INF\netnwifi.PNF, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = INF\netnwifi.PNF, _String2 = $NtUninstallQ923283$, _MaxCount = 0xf, ret_val_out = 69
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc44, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eee5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eee5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x84c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002a692d0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a692d0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xac8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001a8b5f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a8b5f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xc18, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
PsGetCurrentProcessret_val_out = 0xfffffa8002ee1400
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x35c
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xa58, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002304a80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #602 (length: 431, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length431
Processes
+
ProcessAmount
Process 41 (googleupdate.exe, PID: 2440)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x18dfb0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0x40f92c, Length = 0x108, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fc0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52fa0, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x20, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003eec580, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003eec580, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d2578, Length_ptr = 0x64, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x988
_wcsnicmp_String1 = Program Files (x86)\Google\Update\1.3.26.9\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
PsGetCurrentProcessIdret_val_unk_out = 0x988
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x77b52f80, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f03960, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f03960, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f5b0, Length_ptr = 0x1c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003ef1300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef1300, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x76711870, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ProbeForReadAddress_ptr = 0x18dc98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xd3090, Length_ptr = 0x2c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a00030b6f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030b6f0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003e71810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003e71810, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x18dfa8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoAllocateMdlVirtualAddress_ptr = 0x18e830, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8003288b60
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, AccessMode_unk = 0xfffffa8003288b01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8003288b60, MemoryDescriptorList_unk_out = 0xfffffa8003288b60
IoFreeMdlMdl_unk = 0xfffffa8003288b60
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
IoAllocateMdlVirtualAddress_ptr = 0x764c0350, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002721a20
ExGetPreviousModeret_val_unk_out = 0xfffffa80030a5101
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, AccessMode_unk = 0xfffffa8002721a01, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002721a20, MemoryDescriptorList_unk_out = 0xfffffa8002721a20
IoFreeMdlMdl_unk = 0xfffffa8002721a20
ProbeForReadAddress_ptr = 0x18df38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d186c, Length_ptr = 0x20, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001822ca0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822ca0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001a84620, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a84620, ret_val_ptr_out = 0xd
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f760, Length_ptr = 0x18, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f09570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f09570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f434, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f57fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f57fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d31c0, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x988
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1d31c0, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x988
_wcsnicmp_String1 = Windows\SysWOW64\sechost.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\sechost.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x28, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a001f3ec90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f3ec90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessret_val_out = 0xfffffa8002465060
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f094, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f0fc00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0fc00, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40ed68, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f59da0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59da0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40ea3c, Length_ptr = 0x1a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f68610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f68610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f760, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a000bf4fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf4fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f3c0, Length_ptr = 0x16, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f59ec0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f59ec0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40f020, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a000bf3de0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000bf3de0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40ecf4, Length_ptr = 0x14, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f13fc0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f13fc0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40ecf4, Length_ptr = 0xe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003f0f800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003f0f800, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18e840, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40e9c8, Length_ptr = 0x12, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
PsGetCurrentProcessIdret_val_unk_out = 0x988
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88002bffa80, Object_out = 0xfffff8a003ef0610, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a003ef0610, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x18df38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x40e914, Length_ptr = 0x8e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x988
Execution Path #604 (length: 4880, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length4880
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8002eb5890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb5890, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff378, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22ff1d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fecd8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22feb38, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d59e0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff438, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x22ff480, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffffa8003117590, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003117590, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff038, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee98, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x22ff028, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x22fee88, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x490, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003f30a80, Object_out = 0xfffff8a001f03ea0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03ea0, ret_val_ptr_out = 0x1
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #605 (length: 476, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length476
Processes
+
ProcessAmount
Process 13 (svchost.exe, PID: 684)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f1e8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f1e8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce48c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce48c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f438c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f438c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cef530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cef530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf78c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf78c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d03530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d03530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cfb8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cfb8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001aa9060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001aa9060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001aa98c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001aa98c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001b87060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b87060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0019d6060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019d6060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001e28530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e28530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf18c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf18c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0017fb530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fb530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f47320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f47320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00181b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00181b060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001e528c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e528c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0011e3060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0011e3060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f028c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f028c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f438c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f438c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce98c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce98c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce28c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce28c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f44060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f44060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd2530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce0530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce0530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cec8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf7530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf7530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cfb8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cfb8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f4f060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f4f060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cec060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cec060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d05530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d05530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a00181b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00181b060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce2530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce2530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd8530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd8530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cda530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cda530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x5fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f1e530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f1e530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d28060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d28060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001a218c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a218c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2a060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2a060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f05060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2b060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f188c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f188c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x600, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2c060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cf3530, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cf3530, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2c8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2b060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2b060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001a9a8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a9a8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f47320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f47320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a0019d0060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019d0060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ec8060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec8060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001f05060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001844060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001844060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d2c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d2c8c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd88c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd88c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001cd28c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001cd28c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d038c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d038c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001ce08c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ce08c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x2ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x608, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880047a3a80, Object_out = 0xfffff8a001d078c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001d078c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #545 (length: 14, amount: 1, processes: 1)
+
InformationValue
Sequence Length14
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789030, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789090, Object_out = 0xfffff8a001665ef0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001665ef0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #546 (length: 76, amount: 1, processes: 1)
+
InformationValue
Sequence Length76
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000474, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789120, Object_out = 0xfffff8a001695510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001695510, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000047c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004789120, Object_out = 0xfffff8a001287600, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001287600, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000045c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004788f20, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000464, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88004788f20, Object_out = 0xfffffa8002e40350, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e40350, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Kernel Graph 19
No Kernel Graph Available
Code Block #23 ( EP #52)
+
InformationValue
TriggerKiSystemServiceExit+0x1a6
Start Address0xfffffa8001be4478
Execution Path #52 (length: 40, amount: 1, processes: 1)
+
InformationValue
Sequence Length40
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001820000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 20
No Kernel Graph Available
Code Block #24 ( EP #53)
+
InformationValue
Trigger_wcsicmp+0x44
Start Address0xfffffa8001be1ece
Execution Path #53 (length: 364, amount: 1, processes: 1)
+
InformationValue
Sequence Length364
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001ec8ba0, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001f52000, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x36, KeyValueInformation_ptr_out = 0xfffff8a0016abb00, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x2a, KeyValueInformation_deref_Data_out = \Device\NdisWanIpv6, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8010, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001b9ba90, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001b9ba00, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x32, KeyValueInformation_ptr_out = 0xfffff8a0016abb00, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x26, KeyValueInformation_deref_Data_out = \Device\NdisWanBh, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c97e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97c0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007ec, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff880022c94e8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9110, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007ec, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a0019cf5f0, ResultLength_ptr_out = 0xfffff880022c9860, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a0019cf500, Object_ptr_out = 0xfffff880022c9460, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9590, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9808, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001ec8ba0, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *IfType, DestinationString_out = *IfType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x6, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *MediaType, DestinationString_out = *MediaType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9810, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c97e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *PhysicalMediaType, DestinationString_out = *PhysicalMediaType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2c590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2c59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c97c0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 21
No Kernel Graph Available
Code Block #25 ( EP #54)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x704
Start Address0xfffff800026dd620
Execution Path #54 (length: 1, amount: 107, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)107
Sequence
+
SymbolParameters
RtlInitUnicodeStringSourceString = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8, DestinationString_out = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8
Kernel Graph 22
No Kernel Graph Available
Code Block #26 ( EP #55)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x6fe
Start Address0xfffff800026c46a0
Execution Path #55 (length: 1, amount: 52, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)52
Sequence
+
SymbolParameters
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9908, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\NetworkCards\8, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c98e0, KeyHandle_out = 0xffffffff800007ec, ret_val_unk_out = 0x0
Kernel Graph 23
No Kernel Graph Available
Code Block #27 ( EP #56)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x88a
Start Address0xfffff800026c4740
Execution Path #56 (length: 1, amount: 73, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)73
Sequence
+
SymbolParameters
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007ec, ValueName = Description, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c98c0, ret_val_unk_out = 0xc0000023
Kernel Graph 24
No Kernel Graph Available
Code Block #28 ( EP #57, #200)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x6f2
Start Address0xfffff800026c4640
Execution Path #57 (length: 8, amount: 53, processes: 1)
+
InformationValue
Sequence Length8
Processes
+
ProcessAmount
Process 2 (System, PID: 4)53
Sequence
+
SymbolParameters
ZwCloseHandle_unk = 0xffffffff800007ec, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96c0, Object_out = 0xfffff8a001ba27f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba27f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #200 (length: 411, amount: 1, processes: 1)
+
InformationValue
Sequence Length411
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3ae870, Length_ptr = 0xba, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37b110, Length_ptr = 0x100, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37b330, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 25
No Kernel Graph Available
Code Block #29 ( EP #58)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x740
Start Address0xfffff8000271b1b0
Execution Path #58 (length: 1, amount: 5, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
wcsncpy_Source = Red Hat VirtIO Ethernet Adapter, _Count = 0x100, _Dest_out = Red Hat VirtIO Ethernet Adapter, ret_val_out = Red Hat VirtIO Ethernet Adapter
Kernel Graph 26
No Kernel Graph Available
Code Block #30 ( EP #59)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x842
Start Address0xfffff8000271a300
Execution Path #59 (length: 1, amount: 5, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
_snprintf_Count = 0x73, _Format = \Device\NamedPipe\%s, _Dest_out = \Device\NamedPipe\isapi_dg, ret_val_out = 26
Kernel Graph 27
No Kernel Graph Available
Code Block #31 ( EP #60)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x938
Start Address0xfffff8000269bbc8
Execution Path #60 (length: 1, amount: 5, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
RtlInitAnsiStringDestinationString_ptr = 0xfffff880022c9670, SourceString_unk = 0xfffff880022c9920
Kernel Graph 28
No Kernel Graph Available
Code Block #32 ( EP #61)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x932
Start Address0xfffff800029b4248
Execution Path #61 (length: 1, amount: 5, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001b8cc48, SourceString = \Device\NamedPipe\isapi_dg, AllocateDestinationString = 1, ret_val_unk_out = 0x0
Kernel Graph 29
No Kernel Graph Available
Code Block #33 ( EP #62)
+
InformationValue
Triggerunknown_0xfffffa8001bde000+0x2e0
Start Address0xfffff8000267a28c
Execution Path #62 (length: 1, amount: 10, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)10
Sequence
+
SymbolParameters
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8001accec0
Kernel Graph 30
No Kernel Graph Available
Code Block #34 ( EP #63)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x81e
Start Address0xfffff8000270c6dc
Execution Path #63 (length: 1, amount: 40, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)40
Sequence
+
SymbolParameters
_vsnprintfcount = 0x21, format = %u, ap_unk = 0xfffff880022c98d8, string_out = 1, ret_val_out = 1
Kernel Graph 31
No Kernel Graph Available
Code Block #35 ( EP #64)
+
InformationValue
Triggerunknown_0xfffffa8001bdd000+0xc3f
Start Address0xfffff800026d8540
Execution Path #64 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80031273d0
Kernel Graph 32
No Kernel Graph Available
Code Block #36 ( EP #65)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xa5a
Start Address0xfffff8000296a9b0
Execution Path #65 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001e14060, ThreadHandle_ptr_out = 0xfffffa8001c2e420, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
Code Block #9 ( EP #572, #50, #574, #576, #577, #584)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bc88f4
Execution Path #572 (length: 3, amount: 3, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)3
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002f81b50
randret_val_out = 17888
PsTerminateSystemThreadExitStatus_unk = 0x0
Execution Path #50 (length: 2199, amount: 1, processes: 1)
+
InformationValue
Sequence Length2199
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa80030e9a00
randret_val_out = 12425
KeGetCurrentIrqlret_val_unk_out = 0x0
PsCreateSystemThreadDesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System
RtlInitUnicodeStringSourceString = \Device\Null, DestinationString_out = \Device\Null
IoGetDeviceObjectPointerObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObfReferenceObjectObject_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002db2820
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003062510
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa800303a160
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003133510
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 13, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 09, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 31, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 03, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 33, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 7d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 16, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 0c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 29, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par1, ret_val_out = 8
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par2, ret_val_out = 8
_snwprintf_Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62
RtlInitUnicodeStringSourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlQueryRegistryValuesRelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlNtStatusToDosErrorStatus_unk = 0x0, ret_val_out = 0x0
RtlInitUnicodeStringSourceString = \SystemRoot, DestinationString_out = \SystemRoot
ZwOpenSymbolicLinkObjectDesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0
ZwQuerySymbolicLinkObjectSymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0
wcsncpy_Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows
strncpy_Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
_snwprintf_Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20
_snwprintf_Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32
RtlInitUnicodeStringSourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$
ZwOpenFileDesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfReferenceObjectObject_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa
ObfReferenceObjectObject_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa80030e9a00
IoAllocateMdlVirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #574 (length: 38, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa800311f640
randret_val_out = 25331
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0
Execution Path #576 (length: 3, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002fc83c0
randret_val_out = 11502
KeWaitForSingleObjectObject_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0
Execution Path #577 (length: 82, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length82
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8003177620
randret_val_out = 5970
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001b86598
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001820b68
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001e9a6f8
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000
Execution Path #584 (length: 1613, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1613
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002e72880
randret_val_out = 14463
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Code Block #13 ( EP #573)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bdfef4
Execution Path #573 (length: 739, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length739
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -27
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = 63
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0
PsTerminateSystemThreadExitStatus_unk = 0x0
Kernel Graph 33
No Kernel Graph Available
Code Block #37 ( EP #66, #67)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x87e
Start Address0xfffff800026c4b20
Execution Path #66 (length: 1, amount: 5, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f53000, ResultLength_ptr_out = 0xfffff880022c9898, ret_val_unk_out = 0xc0000004
Execution Path #67 (length: 3, amount: 5, processes: 1)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f53000, ResultLength_ptr_out = 0xfffff880022c9898, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa80030e9a00
Kernel Graph 34
No Kernel Graph Available
Code Block #38 ( EP #68)
+
InformationValue
Triggerunknown_0xfffffa8001be4000+0x7e7
Start Address0xfffff8800150a010
Execution Path #68 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
NdisAllocateNetBufferListPoolret_val_out = 0xfffffa8003205e00
Kernel Graph 35
No Kernel Graph Available
Code Block #39 ( EP #69)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xaed
Start Address0xfffff80002719490
Execution Path #69 (length: 1, amount: 40, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)40
Sequence
+
SymbolParameters
KfRaiseIrqlNewIrql_unk = 0xfffff88001517d02, ret_val_unk_out = 0x0
Kernel Graph 36
No Kernel Graph Available
Code Block #40 ( EP #70)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x836
Start Address0xfffff8000271acc0
Execution Path #70 (length: 1, amount: 392, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)392
Sequence
+
SymbolParameters
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
Kernel Graph 37
No Kernel Graph Available
Code Block #41 ( EP #71)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xc39
Start Address0xfffff800026e6fe0
Execution Path #71 (length: 1, amount: 16, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)16
Sequence
+
SymbolParameters
IoAllocateMdlVirtualAddress_ptr = 0xfffff88001517d90, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
Kernel Graph 38
No Kernel Graph Available
Code Block #42 ( EP #72)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xc5b
Start Address0xfffff800026e85f0
Execution Path #72 (length: 1, amount: 16, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)16
Sequence
+
SymbolParameters
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
Kernel Graph 39
No Kernel Graph Available
Code Block #43 ( EP #73)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xc96
Start Address0xfffff800026e9de0
Execution Path #73 (length: 1, amount: 16, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)16
Sequence
+
SymbolParameters
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
Kernel Graph 40
No Kernel Graph Available
Code Block #44 ( EP #74)
+
InformationValue
Triggerunknown_0xfffffa8001bc8000+0xc9f
Start Address0xfffff800026e6e20
Execution Path #74 (length: 1, amount: 16, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)16
Sequence
+
SymbolParameters
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
Kernel Graph 41
No Kernel Graph Available
Code Block #45 ( EP #75)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0xa9f
Start Address0xfffff8800157a730
Execution Path #75 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
NdisInitializeWrapperret_val_out = 0xfffffa8003287178
Kernel Graph 42
No Kernel Graph Available
Code Block #46 ( EP #76)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0xbb9
Start Address0xfffff880015805a0
Execution Path #76 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisMRegisterMiniportret_val_out = 0x0
Kernel Graph 43
No Kernel Graph Available
Code Block #47 ( EP #77)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0xbd1
Start Address0xfffff80002670e70
Execution Path #77 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
IoGetDriverObjectExtensionDriverObject_unk = 0xfffffa8002513880, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa800326c460
Kernel Graph 44
No Kernel Graph Available
Code Block #48 ( EP #78)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0xbed
Start Address0xfffff8000277f0e0
Execution Path #78 (length: 1, amount: 1887, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1887
Sequence
+
SymbolParameters
MmIsAddressValidVirtualAddress_ptr = 0xfffffa800326c460, ret_val_out = 1
Kernel Graph 45
No Kernel Graph Available
Code Block #49 ( EP #81)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0xe2f
Start Address0xfffff8800154d2e0
Execution Path #81 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
NdisTerminateWrapperret_val_out = 0xfffffa80030e9a50
Kernel Graph 46
No Kernel Graph Available
Code Block #50 ( EP #82)
+
InformationValue
Triggerunknown_0xfffffa8001beb000+0x4d6
Start Address0xfffff880014f4940
Execution Path #82 (length: 1, amount: 3, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)3
Sequence
+
SymbolParameters
NdisGetVersionret_val_out = 0x60014
Kernel Graph 47
No Kernel Graph Available
Code Block #51 ( EP #83)
+
InformationValue
Triggerunknown_0xfffffa8001beb000+0x60a
Start Address0xfffff88001517d90
Execution Path #83 (length: 19, amount: 1, processes: 1)
+
InformationValue
Sequence Length19
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisMRegisterMiniportDriver
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c92f0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c92f0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
IoGetDriverObjectExtensionDriverObject_unk = 0xfffffa8002513880, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa8002f8bcd0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
Kernel Graph 48
No Kernel Graph Available
Code Block #52 ( EP #84)
+
InformationValue
TriggerMiIsAddressValid+0xa8
Start Address0xfffffa8001beb6bd
Execution Path #84 (length: 604, amount: 1, processes: 1)
+
InformationValue
Sequence Length604
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd69, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd6f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd71, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcda, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd72, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcdb, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd73, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcdc, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd74, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcdd, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd75, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcde, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd76, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcdf, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd77, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd79, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd7f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd81, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcea, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd82, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bceb, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd83, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcec, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd84, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bced, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd85, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcee, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd86, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcef, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd87, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd89, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd8f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd91, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcfa, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd92, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcfb, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd93, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcfc, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd94, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcfd, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd95, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcfe, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd96, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcff, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd97, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd01, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd99, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd02, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd03, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd04, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd05, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd06, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd07, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd9f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd09, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd0f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd11, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd12, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdaa, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd13, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdab, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd14, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdac, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd15, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdad, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd16, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdae, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd17, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdaf, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd19, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd1f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd21, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd22, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdba, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd23, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdbb, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd24, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdbc, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd25, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdbd, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd26, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdbe, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd27, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdbf, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd29, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd2f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd31, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc9, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd32, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdca, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd33, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdcb, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd34, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdcc, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd35, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdcd, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd36, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdce, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd37, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdcf, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd39, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd1, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3a, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd2, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3b, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd3, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3c, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd4, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3d, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd5, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3e, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd6, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd3f, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd7, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd18, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd20, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd28, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd30, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd38, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd40, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd48, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd50, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd58, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd60, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd68, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd70, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd78, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd80, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd88, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd90, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd98, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bda8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdb8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bdc0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcd8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bce8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf0, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bcf8, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd00, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd08, ret_val_out = 1
MmIsAddressValidVirtualAddress_ptr = 0xfffffa8002f8bd10, ret_val_out = 1
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffffa8002f8bd02, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x2
KeLowerIrqlNewIrql_unk = 0x0
NdisMDeregisterMiniportDriver
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
Kernel Graph 49
No Kernel Graph Available
Code Block #53 ( EP #85, #86, #110, #285, #349, #372, #519, #521, #527, #530)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x7d6
Start Address0xfffff800026c4aa0
Execution Path #85 (length: 55, amount: 5, processes: 1)
+
InformationValue
Sequence Length55
Processes
+
ProcessAmount
Process 2 (System, PID: 4)5
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c95e0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d8, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff880022c9268, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0000, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0001, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0002, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0003, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0004, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0005, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0006, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0007, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0008, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0009, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0010, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = 0011, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Properties, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8e90, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #86 (length: 6, amount: 163, processes: 1)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 2 (System, PID: 4)163
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d8, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c95e0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c91e0, Object_out = 0xfffff8a000d29760, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000d29760, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #110 (length: 22, amount: 7, processes: 1)
+
InformationValue
Sequence Length22
Processes
+
ProcessAmount
Process 2 (System, PID: 4)7
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001a795d0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a79500, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #285 (length: 186, amount: 1, processes: 1)
+
InformationValue
Sequence Length186
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f3a010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14cd4b0, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
Execution Path #349 (length: 562, amount: 1, processes: 1)
+
InformationValue
Sequence Length562
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16104f0, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16235e0, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144f920, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16170c0, Length_ptr = 0xb4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #372 (length: 520, amount: 1, processes: 1)
+
InformationValue
Sequence Length520
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFontCache, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x80, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemDrawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x81, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x82, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemXmlLinq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x83, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Aero, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x84, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Aero, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x85, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.AeroLite, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x86, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Classic, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x87, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Classic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x88, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Luna, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x89, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Luna, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Royale, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Royale, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationUI, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationUI, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ReachFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x8f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ReachFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x90, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SecurityAuditPoliciesSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x91, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMDiagnostics, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x92, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMDiagnostics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x93, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMSvcHost, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x94, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SrpUxSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x95, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x96, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x97, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x98, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.Core.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x99, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn.Contract, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn.Contract, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x9f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.Composition, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.Composition.Registration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.DataAnnotations, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.DataAnnotations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration.Install, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration.Install, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Core, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xa9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xaa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xab, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.DataSetExtensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xac, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.DataSetExtensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xad, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xae, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
Execution Path #519 (length: 549, amount: 1, processes: 1)
+
InformationValue
Sequence Length549
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x68, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Workflow.Compiler, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x69, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.WSMan.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.WSMan.Runtime, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MiguiControls, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MMCEx, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MMCFxCommon, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MSBuild, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x6f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mscorlib, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x70, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x71, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napcrypt, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x72, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = naphlpr, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x73, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napinit, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x74, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napsnap, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x75, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Narrator, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x76, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationBuildTasks, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x77, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationBuildTasks, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x78, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCFFRasterizer, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x79, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCore, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFontCache, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x7f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemData, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x80, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemDrawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x81, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x82, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework-SystemXmlLinq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x83, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Aero, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x84, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Aero, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x85, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.AeroLite, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x86, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Classic, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x87, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Classic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x88, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Luna, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x89, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Luna, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Royale, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationFramework.Royale, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationUI, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationUI, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ReachFramework, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x8f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ReachFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x90, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SecurityAuditPoliciesSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x91, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMDiagnostics, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x92, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMDiagnostics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x93, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SMSvcHost, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x94, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = SrpUxSnapIn, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x95, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x96, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x97, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x98, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.Core.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x99, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Activities.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.AddIn.Contract, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #521 (length: 110, amount: 1, processes: 1)
+
InformationValue
Sequence Length110
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x13f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WindowsFormsIntegration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x140, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WsatConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x141, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = XamlBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x142, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = XsdBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x100, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30e130, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #527 (length: 172, amount: 1, processes: 1)
+
InformationValue
Sequence Length172
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30e400, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #530 (length: 13, amount: 1, processes: 1)
+
InformationValue
Sequence Length13
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Kernel Graph 50
No Kernel Graph Available
Code Block #54 ( EP #87, #112)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x722
Start Address0xfffff8000271a3ac
Execution Path #87 (length: 1, amount: 80, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)80
Sequence
+
SymbolParameters
_snwprintf_Count = 0x72, _Format = %s\%s\%s, _Dest_out = \REGISTRY\MACHINE\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ret_val_out = 108
Execution Path #112 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0006, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x7, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0007, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x8, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0008, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x9, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 51
No Kernel Graph Available
Code Block #55 ( EP #88)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x8e4
Start Address0xfffff8000271b2a4
Execution Path #88 (length: 1, amount: 24, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)24
Sequence
+
SymbolParameters
wcsstr_Str = \Device\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}, _SubStr = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}
Kernel Graph 52
No Kernel Graph Available
Code Block #56 ( EP #89)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x6f8
Start Address0xfffff800026c5060
Execution Path #89 (length: 1, amount: 6, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)6
Sequence
+
SymbolParameters
ZwSetValueKeyKeyHandle_unk = 0xffffffff800007d8, ValueName = UpperBind, TitleIndex = 0x0, Type = 0x7, Data = Ndisuio, DataSize = 0x6c, ret_val_unk_out = 0x0
Kernel Graph 53
No Kernel Graph Available
Code Block #57 ( EP #92)
+
InformationValue
Triggerunknown_0xfffffa8001be8000+0xca8
Start Address0xfffff8800157fc40
Execution Path #92 (length: 15, amount: 1, processes: 1)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisRegisterProtocolDriverret_val_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9580, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9580, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 54
No Kernel Graph Available
Code Block #58 ( EP #93)
+
InformationValue
Triggerunknown_0xfffffa8001bea000+0x10b
Start Address0xfffff8800157f880
Execution Path #93 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
NdisRegisterProtocolret_val_out = 0xfffffa80030e9a50
Kernel Graph 55
No Kernel Graph Available
Code Block #59 ( EP #98)
+
InformationValue
Triggerunknown_0xfffffa8001bea000+0x32b
Start Address0xfffff88001583630
Execution Path #98 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisDeregisterProtocolret_val_out = 0xfffffa80030e9a50
Kernel Graph 56
No Kernel Graph Available
Code Block #60 ( EP #96)
+
InformationValue
TriggerndisInitializeBindingEx+0x713
Start Address0xfffffa8001be8b54
Execution Path #96 (length: 577, amount: 1, processes: 1)
+
InformationValue
Sequence Length577
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, _Count = 0x104, _Dest_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ret_val_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
RtlInitUnicodeStringSourceString = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, DestinationString_out = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
NdisMGetDevicePropertyret_val_out = 0xfffffa8001f5b050
IoGetDriverObjectExtensionDriverObject_unk = 0xfffffa8003106060, ClientIdentificationAddress_ptr = 0x4e4d4944, ret_val_ptr_out = 0xfffffa80031aaa10
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f71ac, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 3d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = be, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 74, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f7102, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f71ac, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f7754, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 3d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f9, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f7702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f7754, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f78f8, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 3d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 13, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b7, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 74, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f7802, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f78f8, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f8250, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 74, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 41, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 56, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f8202, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f8250, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f781c, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 74, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 57, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 3d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e6, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b7, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f7802, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f781c, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
MmIsAddressValidVirtualAddress_ptr = 0xfffff880038f7110, ret_val_out = 1
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bb, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = cc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = cc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = cc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 53, ret_val_out = 2
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff880038f7102, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bb, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bb, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff880038f7110, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c3c700
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2e000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8001872ba0
NdisOidRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa8001872ba0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001872ba0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001872ba0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
Kernel Graph 57
No Kernel Graph Available
Code Block #61 ( EP #99)
+
InformationValue
Triggerunknown_0xfffffa8001be9000+0x439
Start Address0xfffff88001580470
Execution Path #99 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisIMRegisterLayeredMiniportret_val_out = 0xc000009a
Kernel Graph 58
No Kernel Graph Available
Code Block #62 ( EP #100)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x7f4
Start Address0xfffff800026c4800
Execution Path #100 (length: 2, amount: 4, processes: 1)
+
InformationValue
Sequence Length2
Processes
+
ProcessAmount
Process 2 (System, PID: 4)4
Sequence
+
SymbolParameters
ZwCreateKeyDesiredAccess_unk = 0xf003f, ObjectAttributes_ptr = 0xfffff880022c93e0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\System\CurrentControlSet\Services\filter_c06b1a3b, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, TitleIndex = 0x0, Class_ptr = 0x0, CreateOptions = 0x0, KeyHandle_ptr_out = 0xfffff880022c9668, KeyHandle_out = 0xffffffff800007d8, Disposition_ptr_out = 0xfffff880022c9650, Disposition_out = 0x1, ret_val_unk_out = 0x0
ExGetPreviousModeret_val_unk_out = 0xfffffa80030e9a00
Kernel Graph 59
No Kernel Graph Available
Code Block #63 ( EP #101)
+
InformationValue
Triggerunknown_0xfffffa8001bea000+0xd20
Start Address0xfffff8800151e9d0
Execution Path #101 (length: 78, amount: 1, processes: 1)
+
InformationValue
Sequence Length78
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisFRegisterFilterDriverret_val_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7510, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a0013d7510, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7510, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91a0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9170, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c90d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c90e0, Object_out = 0xfffff8a001b6f0f0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b6f0f0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800001ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c91d0, Object_out = 0xfffff8a0013d7200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 60
No Kernel Graph Available
Code Block #64 ( EP #102)
+
InformationValue
Triggerunknown_0xfffffa8001beb000+0x1d5
Start Address0xfffff8800151c7c0
Execution Path #102 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisFDeregisterFilterDriverret_val_out = 0x0
Kernel Graph 61
No Kernel Graph Available
Code Block #65 ( EP #103)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x728
Start Address0xfffff800026c5b20
Execution Path #103 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
ZwDeleteKeyKeyHandle_unk = 0xffffffff800001ac, ret_val_unk_out = 0xc0000121
Kernel Graph 62
No Kernel Graph Available
Code Block #66 ( EP #104)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x8f0
Start Address0xfffff8000296acbc
Execution Path #104 (length: 1, amount: 4, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)4
Sequence
+
SymbolParameters
RtlCompareUnicodeStringString1 = \Driver\Psched, String2 = \Driver\NativeWifiP, CaseInsensitive = 0, ret_val_out = 2
Kernel Graph 63
No Kernel Graph Available
Code Block #67 ( EP #105)
+
InformationValue
Triggerunknown_0xfffffa8001bf4000+0xc0e
Start Address0xfffff880014d6720
Execution Path #105 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisAllocatePacketPoolret_val_out = 0xfffffa8002bf7160
Kernel Graph 64
No Kernel Graph Available
Code Block #68 ( EP #106)
+
InformationValue
Triggerunknown_0xfffffa8001bf4000+0xc32
Start Address0xfffff880014d6460
Execution Path #106 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
NdisAllocateBufferPoolret_val_out = 0x0
Kernel Graph 65
No Kernel Graph Available
Code Block #69 ( EP #107)
+
InformationValue
Triggerunknown_0xfffffa8001be2000+0xbd2
Start Address0xfffff88001437270
Execution Path #107 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
GetIfTable2ret_val_out = 0x0
Kernel Graph 66
No Kernel Graph Available
Code Block #70 ( EP #108)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x8c6
Start Address0xfffff800029a8aec
Execution Path #108 (length: 1, amount: 36, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)36
Sequence
+
SymbolParameters
RtlMultiByteToUnicodeNMaxBytesInUnicodeString = 0x4c, MultiByteString = {9a399d81-2ead-4f23-bcdd-637fc13dcd51}, BytesInMultiByteString = 0x26, UnicodeString_out = {9a399d81-2ead-4f23-bcdd-637fc13dcd51}, BytesInUnicodeString_ptr_out = 0xfffff880022c9140, ret_val_unk_out = 0x0
Kernel Graph 67
No Kernel Graph Available
Code Block #71 ( EP #109)
+
InformationValue
Triggerunknown_0xfffffa8001be2000+0xceb
Start Address0xfffff88001423fd0
Execution Path #109 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)2
Sequence
+
SymbolParameters
FreeMibTableret_val_out = 0x15083a0
Kernel Graph 68
No Kernel Graph Available
Code Block #72 ( EP #111)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x758
Start Address0xfffff80002699750
Execution Path #111 (length: 1, amount: 8, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 2 (System, PID: 4)8
Sequence
+
SymbolParameters
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
Kernel Graph 69
No Kernel Graph Available
Code Block #73 ( EP #113)
+
InformationValue
TriggerKiSystemServiceExit+0x1a6
Start Address0xfffffa8001be4659
Execution Path #113 (length: 573, amount: 1, processes: 1)
+
InformationValue
Sequence Length573
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0009, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0xa, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0010, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0xb, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6b, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0011, ret_val_out = 100
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0xc, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x77, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\Properties, ret_val_out = 106
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0xd, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00183c000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001630000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0000\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{71F897D7-EB7C-4D8D-89DB-AC80D9DD2270}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001ed4be0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ed4b00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0001\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a00115e050, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{29898C9D-B0A4-4FEF-BDB6-57A562022CEE}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a00030abe0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a00030ab00, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0002\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{E43D242B-9EAB-4626-A952-46649FBB939A}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0cbf0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bce1c0, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bce100, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0003\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a00115e050, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{DF4A9D2C-8742-4EB1-8703-D395C4183F33}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a000304000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0004\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x6c, KeyValueInformation_ptr_out = 0xfffff8a001842780, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x60, KeyValueInformation_deref_Data_out = \Device\{8E301A52-AFFA-4F49-B9CA-C79096A1A056}, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
ZwOpenKeyDesiredAccess_unk = 0x8, ObjectAttributes_ptr = 0xfffff880022c91f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91d0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007d4, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff880022c8ef8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Linkage, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -9
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
wcsncmp_String1 = Ndi, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8b20, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x400, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x76, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ret_val_out = 108
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_snwprintf_Count = 0x6e, _Format = %s\%s, _Dest_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Ndi, ret_val_out = 104
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007d4, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x418, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff880022c9270, ret_val_unk_out = 0x8000001a
PsGetCurrentProcessIdret_val_unk_out = 0x4
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001bfb000, Object_ptr_out = 0xfffff880022c8e70, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fa0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
_wcsicmp_Str1 = Linkage, _Str2 = Linkage, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9218, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005\Linkage, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = Export, DestinationString_out = Export
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = Export, KeyValueInformationClass_unk = 0x2, Length = 0x36, KeyValueInformation_ptr_out = 0xfffff8a001ec2620, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x7, KeyValueInformation_deref_DataLength_out = 0x2a, KeyValueInformation_deref_Data_out = \Device\NdisWanIpv6, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *IfType, DestinationString_out = *IfType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *IfType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x6, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *MediaType, DestinationString_out = *MediaType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *MediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, DestinationString_out = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005
ZwOpenKeyDesiredAccess_unk = 0x1, ObjectAttributes_ptr = 0xfffff880022c9220, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Registry\Machine\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}\0005, ObjectAttributes_deref_Attributes = 0x140, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, KeyHandle_ptr_out = 0xfffff880022c91f0, KeyHandle_out = 0xffffffff800007d4, ret_val_unk_out = 0x0
RtlInitUnicodeStringSourceString = *PhysicalMediaType, DestinationString_out = *PhysicalMediaType
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x0, KeyValueInformation_ptr_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0xc0000023
ZwQueryValueKeyKeyHandle_unk = 0xffffffff800007d4, ValueName = *PhysicalMediaType, KeyValueInformationClass_unk = 0x2, Length = 0x10, KeyValueInformation_ptr_out = 0xfffff8a001f2e590, KeyValueInformation_deref_TitleIndex_out = 0x0, KeyValueInformation_deref_Type_out = 0x4, KeyValueInformation_deref_DataLength_out = 0x4, KeyValueInformation_deref_Data_ptr_out = 0xfffff8a001f2e59c, KeyValueInformation_deref_Data_out = 0x0, ResultLength_ptr_out = 0xfffff880022c91d0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007d4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8fd0, Object_out = 0xfffff8a00166a2e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00166a2e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8002b931f0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
_wcsicmp_Str1 = \Device\NdisWanIp, _Str2 = \Device\NdisWanBh, ret_val_out = 7
_wcsicmp_Str1 = \Device\NdisWanIp, _Str2 = \Device\{7EC55B5C-7DA9-4C5A-BFD3-421B4A2885A4}, ret_val_out = -13
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = \Device\NdisWanBh, _Count = 0x100, _Dest_out = \Device\NdisWanBh, ret_val_out = \Device\NdisWanBh
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
RtlInitUnicodeStringSourceString = \Device\NdisWanBh, DestinationString_out = \Device\NdisWanBh
NdisOpenAdapterret_val_out = 0xfffff8800152e110
Kernel Graph 70
No Kernel Graph Available
Code Block #74 ( EP #114)
+
InformationValue
TriggerNdisOpenAdapter+0x322
Start Address0xfffffa8001bf4206
Execution Path #114 (length: 104, amount: 1, processes: 1)
+
InformationValue
Sequence Length104
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = NdisWanBh, _Count = 0x100, _Dest_out = NdisWanBh, ret_val_out = NdisWanBh
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
_snwprintf_Count = 0x100, _Format = %S, _Dest_out = NdisWan Adapter, ret_val_out = 15
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = NdisWan Adapter, _Count = 0x100, _Dest_out = NdisWan Adapter, ret_val_out = NdisWan Adapter
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = \Device\NdisWanIp, _Count = 0x100, _Dest_out = \Device\NdisWanIp, ret_val_out = \Device\NdisWanIp
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
RtlInitUnicodeStringSourceString = \Device\NdisWanIp, DestinationString_out = \Device\NdisWanIp
NdisOpenAdapterret_val_out = 0xfffff8800152e110
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
NdisRequestret_val_out = 0x103
KeSetEventEvent_unk = 0xfffffa800307dda0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa800307dda0, ret_val_out = 0
Kernel Graph 71
No Kernel Graph Available
Code Block #75 ( EP #115)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bf3d2d
Execution Path #115 (length: 402, amount: 1, processes: 1)
+
InformationValue
Sequence Length402
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800307dda0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = NdisWanIp, _Count = 0x100, _Dest_out = NdisWanIp, ret_val_out = NdisWanIp
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
_snwprintf_Count = 0x100, _Format = %S, _Dest_out = NdisWan Adapter, ret_val_out = 15
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
wcsncpy_Source = NdisWan Adapter, _Count = 0x100, _Dest_out = NdisWan Adapter, ret_val_out = NdisWan Adapter
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2d800
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa800307dda0
RtlQueryRegistryValuesRelativeTo = 0x1, Path = Tcpip\Parameters, QueryTable_unk = 0xfffffa8001c3a5e0, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96b0, Object_out = 0xfffff8a0013d7e90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013d7e90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlInitUnicodeStringSourceString = \Device\Nsi, DestinationString_out = \Device\Nsi
IoGetDeviceObjectPointerObjectName = \Device\Nsi, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c99a0, DeviceObject_unk_out = 0xfffffa8001c2e380, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c96b0, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObfReferenceObjectObject_ptr = 0xfffffa80025607f0, ret_val_ptr_out = 0x3
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa8001c2cee0
strncpy_Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
strncpy_Source = fixdata.dat, _Count = 0x52, _Dest_out = fixdata.dat, ret_val_out = fixdata.dat
_snwprintf_Count = 0x104, _Format = \SystemRoot\%S\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, ret_val_out = 44
RtlInitUnicodeStringSourceString = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, DestinationString_out = \SystemRoot\$NtUninstallQ923283$\fixdata.dat
atoi_Str = 400, ret_val_out = 400
IoCreateFileDesiredAccess_unk = 0x3, ObjectAttributes_ptr = 0xfffff880022c9540, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$\fixdata.dat, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0xfffff880022c98a0, FileAttributes = 0x80, ShareAccess = 0x0, Disposition = 0x3, CreateOptions = 0x868, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff80000000000, InternalParameters_ptr = 0x0, Options = 0x100
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\$NtUninstallQ923283$\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
_wcsnicmp_String1 = Windows\$NtUninstallQ923283$\, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c8760, Object_out = 0xfffffa800279c1c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800279c1c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwSetInformationFileFileHandle_unk = 0xffffffff800007d4, IoStatusBlock_unk = 0xfffff880022c9578, FileInformation_ptr = 0xfffff880022c9570, Length = 0x8, FileInformationClass_unk = 0xfffff88000000014, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
ZwCreateSectionDesiredAccess_unk = 0x6, ObjectAttributes_ptr = 0xfffff880022c9540, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName_ptr = 0x0, ObjectAttributes_deref_Attributes = 0x0, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, MaximumSize_ptr = 0x0, SectionPageProtection = 0x4, AllocationAttributes = 0x18000000, FileHandle_unk = 0xffffffff800007d4, SectionHandle_ptr_out = 0xfffffa8001c2ce88, SectionHandle_out = 0xffffffff800007e0, ret_val_unk_out = 0x0
ZwMapViewOfSectionSectionHandle_unk = 0xffffffff800007e0, ProcessHandle_unk = 0xffffffffffffffff, ZeroBits = 0x0, CommitSize = 0x0, InheritDisposition_unk = 0xfffff88000000002, AllocationType = 0x0, AccessProtection = 0x4, BaseAddress_ptr_out = 0xfffffa8001c2ce98, BaseAddress_out = 0x90000, SectionOffset_out = 0x0, ViewSize_ptr_out = 0xfffff880022c98a8, ViewSize_out = 0x19000000, ret_val_unk_out = 0x0
Kernel Graph 72
No Kernel Graph Available
Code Block #76 ( EP #140)
+
InformationValue
TriggerRtlInitUnicodeString+0x52
Start Address0xfffffa8001bdd5a2
Execution Path #140 (length: 65, amount: 1, processes: 1)
+
InformationValue
Sequence Length65
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
IoCreateDeviceDriverObject_unk = 0xfffffa8002513880, DeviceExtensionSize = 0x0, DeviceName = \Device\RawDisk1, DeviceType_unk = 0x7, DeviceCharacteristics = 0x1, Exclusive = 0
_wcsnicmp_String1 = Null, _String2 = netbt, _MaxCount = 0x4, ret_val_out = 16
_wcsnicmp_String1 = Null, _String2 = afd, _MaxCount = 0x4, ret_val_out = 13
_wcsnicmp_String1 = Null, _String2 = Null, _MaxCount = 0x4, ret_val_out = 0
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001f03590, ThreadHandle_ptr_out = 0xfffff880022c9830, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff800007dc, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007dc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffffa80030ddb50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030ddb50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlCreateSecurityDescriptorRevision = 0x1, SecurityDescriptor_unk_out = 0xfffff880022c9850, ret_val_unk_out = 0x0
SeSetSecurityDescriptorInfoObject_ptr = 0xfffffa8003142620, SecurityInformation_unk = 0xfffff880022c9898, ModificationDescriptor_unk = 0xfffff880022c9850, ObjectsSecurityDescriptor_unk = 0xfffffa8003142730, PoolType_unk = 0x1, GenericMapping_unk = 0xfffff880022c9840, ObjectsSecurityDescriptor_unk_out = 0xfffffa8003142730, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
atoi_Str = 16, ret_val_out = 16
ZwCreateSectionDesiredAccess_unk = 0x6, ObjectAttributes_ptr = 0xfffff880022c98f0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName_ptr = 0x0, ObjectAttributes_deref_Attributes = 0x0, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, MaximumSize_ptr = 0xfffffa8001c2ceb0, SectionPageProtection = 0x4, AllocationAttributes = 0x18000000, FileHandle_unk = 0x0, SectionHandle_ptr_out = 0xfffffa8001c2ce90, SectionHandle_out = 0xffffffff800007dc, ret_val_unk_out = 0x0
ZwMapViewOfSectionSectionHandle_unk = 0xffffffff800007dc, ProcessHandle_unk = 0xffffffffffffffff, ZeroBits = 0x0, CommitSize = 0x0, InheritDisposition_unk = 0xfffffa8000000002, AllocationType = 0x0, AccessProtection = 0x4, BaseAddress_ptr_out = 0xfffffa8001c2cea0, BaseAddress_out = 0x19090000, SectionOffset_out = 0x0, ViewSize_ptr_out = 0xfffff880022c9a10, ViewSize_out = 0x1000000, ret_val_unk_out = 0x0
_snwprintf_Count = 0x52, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16
RtlInitUnicodeStringSourceString = \Device\RawDisk2, DestinationString_out = \Device\RawDisk2
IoCreateDeviceDriverObject_unk = 0xfffffa8002513880, DeviceExtensionSize = 0x0, DeviceName = \Device\RawDisk2, DeviceType_unk = 0x7, DeviceCharacteristics = 0x1, Exclusive = 0
_wcsnicmp_String1 = Null, _String2 = netbt, _MaxCount = 0x4, ret_val_out = 16
_wcsnicmp_String1 = Null, _String2 = afd, _MaxCount = 0x4, ret_val_out = 13
_wcsnicmp_String1 = Null, _String2 = Null, _MaxCount = 0x4, ret_val_out = 0
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a0005df400, ThreadHandle_ptr_out = 0xfffff880022c9830, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff80000804, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff80000804, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c95c0, Object_out = 0xfffffa800310aad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800310aad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlCreateSecurityDescriptorRevision = 0x1, SecurityDescriptor_unk_out = 0xfffff880022c9850, ret_val_unk_out = 0x0
SeSetSecurityDescriptorInfoObject_ptr = 0xfffffa8002fb9d80, SecurityInformation_unk = 0xfffff880022c9898, ModificationDescriptor_unk = 0xfffff880022c9850, ObjectsSecurityDescriptor_unk = 0xfffffa8002fb9e90, PoolType_unk = 0x1, GenericMapping_unk = 0xfffff880022c9840, ObjectsSecurityDescriptor_unk_out = 0xfffffa8002fb9e90, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a0005df400, ThreadHandle_ptr_out = 0xfffffa8001c2cef8, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Code Block #9 ( EP #572, #50, #574, #576, #577, #584)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bc88f4
Execution Path #572 (length: 3, amount: 3, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)3
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002f81b50
randret_val_out = 17888
PsTerminateSystemThreadExitStatus_unk = 0x0
Execution Path #50 (length: 2199, amount: 1, processes: 1)
+
InformationValue
Sequence Length2199
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa80030e9a00
randret_val_out = 12425
KeGetCurrentIrqlret_val_unk_out = 0x0
PsCreateSystemThreadDesiredAccess = 0x0, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bdfef4, StartContext_ptr = 0xfffffa8001c2d8d0, ThreadHandle_ptr_out = 0xfffff880022c9b48, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwWaitForSingleObjectHandle_unk = 0xffffffff800007f4, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
strncpy_Source = System, _Count = 0x11, _Dest_out = System, ret_val_out = System
RtlInitUnicodeStringSourceString = \Device\Null, DestinationString_out = \Device\Null
IoGetDeviceObjectPointerObjectName = \Device\Null, DesiredAccess_unk = 0x0, FileObject_unk_out = 0xfffff880022c9b40, DeviceObject_unk_out = 0xfffffa8001c2c540, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObfReferenceObjectObject_ptr = 0xfffffa8002516740, ret_val_ptr_out = 0x3
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002db2820
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f64ce0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003062510
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002e55aa0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8002f7f7b0
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa800303a160
KeInitializeMutexLevel = 0x0, Mutex_unk_out = 0xfffffa8003133510
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4720, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 13, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b56000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b56000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff8000299db02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff8000299db60, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4aa0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b57000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b57000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002986d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002986df0, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4800, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2e, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b58000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b58000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002982802, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002982820, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c6de0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 09, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b59000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b59000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002b4f402, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002b4f440, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4520, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 31, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 03, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5a000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5a000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029b7f02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029b7f80, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4b20, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 33, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5b000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5b000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029d9c02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f3, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029d9cdc, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4780, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 7d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 16, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5c000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5c000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029e0702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 20, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029e0780, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c4640, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bd, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 30, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 0c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5d000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5d000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029c5702, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 08, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029c5740, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff800026c49e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c4, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = fa, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ec, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 9c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 10, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 48, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 29, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff88000000010, ret_val_ptr_out = 0xfffff88000b5e000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5e000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff80002987d02, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 89, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 18, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002987d14, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0xfffff800029ca602, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = dc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 55, ret_val_out = 2
IoAllocateMdlVirtualAddress_ptr = 0xfffff800029ca650, Length = 0x4, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KfRaiseIrqlNewIrql_unk = 0x2, ret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0x0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0xc0000034
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk1, ret_val_out = 16
_snwprintf_Count = 0x104, _Format = \Device\%S, _Dest_out = \Device\RawDisk2, ret_val_out = 16
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par1, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par1, ret_val_out = 8
_snprintf_Count = 0x104, _Format = \??\%s, _Dest_out = \??\Par2, ret_val_out = 8
_swprintf_Format = %S, _Dest_out = \??\Par2, ret_val_out = 8
_snwprintf_Count = 0x104, _Format = \BaseNamedObjects\%S, _Dest_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, ret_val_out = 62
RtlInitUnicodeStringSourceString = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}, DestinationString_out = \BaseNamedObjects\shell.{F21EDC09-85D3-4eb9-915F-1AFA2FF28153}
ZwOpenEventDesiredAccess_unk = 0x1f0003, ObjectAttributes_unk = 0xfffff880022c9790, EventHandle_ptr_out = 0xfffff880022c9a00, ret_val_unk_out = 0x0
ZwCloseHandle_unk = 0xffffffff800007f4, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9560, Object_out = 0xfffffa8002dd1890, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002dd1890, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlQueryRegistryValuesRelativeTo = 0x3, Path = 0x0, QueryTable_unk = 0xfffff880022c9970, Context_ptr = 0x0, Environment_ptr = 0x0, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9660, Object_out = 0xfffff8a0013e0c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013e0c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
RtlNtStatusToDosErrorStatus_unk = 0x0, ret_val_out = 0x0
RtlInitUnicodeStringSourceString = \SystemRoot, DestinationString_out = \SystemRoot
ZwOpenSymbolicLinkObjectDesiredAccess_unk = 0x1, ObjectAttributes_unk = 0xfffff880022c96d0, SymbolicLinkHandle_ptr_out = 0xfffff880022c99a0, ret_val_unk_out = 0x0
ZwQuerySymbolicLinkObjectSymLinkObjHandle_unk = 0xffffffff800007f4, LinkTarget_out = \Device\Harddisk0\Partition2\Windows, DataWritten_ptr_out = 0x0, ret_val_unk_out = 0x0
wcsncpy_Source = Windows, _Count = 0x104, _Dest_out = Windows, ret_val_out = Windows
strncpy_Source = $NtUninstallQ923283$, _Count = 0x52, _Dest_out = $NtUninstallQ923283$, ret_val_out = $NtUninstallQ923283$
_snwprintf_Count = 0x51, _Format = %S, _Dest_out = $NtUninstallQ923283$, ret_val_out = 20
_snwprintf_Count = 0x103, _Format = \SystemRoot\%S, _Dest_out = \SystemRoot\$NtUninstallQ923283$, ret_val_out = 32
RtlInitUnicodeStringSourceString = \SystemRoot\$NtUninstallQ923283$, DestinationString_out = \SystemRoot\$NtUninstallQ923283$
ZwOpenFileDesiredAccess_unk = 0x100000, ObjectAttributes_ptr = 0xfffff880022c96d0, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \SystemRoot\$NtUninstallQ923283$, ObjectAttributes_deref_Attributes = 0x240, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, ShareAccess = 0x7, OpenOptions = 0x21, FileHandle_ptr_out = 0xfffff880022c99a0, FileHandle_out = 0xffffffff80000824, IoStatusBlock_unk_out = 0xfffff880022c9700, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c99a8, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfReferenceObjectObject_ptr = 0xfffffa800202b650, ret_val_ptr_out = 0xa
ObfReferenceObjectObject_ptr = 0xfffffa8002c55030, ret_val_ptr_out = 0x2
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ZwCloseHandle_unk = 0xffffffff80000824, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000824, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880022c9490, Object_out = 0xfffffa8002a65200, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002a65200, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeInitializeEventType_unk = 0x1, State = 0, Event_unk_out = 0xfffffa80026b7660
PsCreateSystemThreadDesiredAccess = 0x1f03ff, ObjectAttributes_unk = 0x0, ProcessHandle_unk = 0x0, StartRoutine_unk = 0xfffffa8001bc88f4, StartContext_ptr = 0xfffff8a001ecfc00, ThreadHandle_ptr_out = 0xfffffa8001c2c210, ClientId_unk_out = 0x0, ret_val_unk_out = 0x0
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x4000, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000004
ZwQuerySystemInformationSystemInformationClass_unk = 0xb, Length_ptr = 0x9530, SystemInformation_ptr_out = 0xfffff8a001f17000, ResultLength_ptr_out = 0xfffff880022c9908, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x4
ExGetPreviousModeret_val_unk_out = 0xfffffa80030e9a00
IoAllocateMdlVirtualAddress_ptr = 0x779a17b0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b5f000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d0, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1d, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ed, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 5f, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = ff, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 49, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = c1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e2, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 05, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = bc, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 1a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 40, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = e9, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 2a, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000b5f000, MemoryDescriptorList_unk = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0x779a17e0, Length = 0x40, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = d1, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = b8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 50, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 00, ret_val_out = 2
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
IoAllocateMdlVirtualAddress_ptr = 0xfffff80002a41000, Length = 0x1000, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, Operation_unk = 0x0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0x10, ret_val_ptr_out = 0xfffff88000b60000
sprintf_Format = %02x, _Dest_out = 8b, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 44, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 24, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 28, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 83, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = f8, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 01, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 77, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 6c, ret_val_out = 2
sprintf_Format = %02x, _Dest_out = 4c, ret_val_out = 2
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #574 (length: 38, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa800311f640
randret_val_out = 25331
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0, ret_val_unk_out = 0x102
RtlNtStatusToDosErrorStatus_unk = 0x102, ret_val_out = 0x5b4
KeAcquireSpinLockRaiseToDpcSpinLock_unk = 0xfffffa8001c2cf30, SpinLock_unk_out = 0xfffffa8001c2cf30, ret_val_unk_out = 0x0
PsGetCurrentThreadIdret_val_unk_out = 0x1a8
KeReleaseSpinLockSpinLock_unk = 0xfffffa8001c2cf30, NewIrql_unk = 0x0, SpinLock_unk_out = 0xfffffa8001c2cf30
KeWaitForSingleObjectObject_ptr = 0xfffffa80026b7660, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0xfffff88002798aa0
Execution Path #576 (length: 3, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002fc83c0
randret_val_out = 11502
KeWaitForSingleObjectObject_ptr = 0xfffffa80031273d0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0
Execution Path #577 (length: 82, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length82
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8003177620
randret_val_out = 5970
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001b865b8, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001b86598
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001820b78, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001820b88, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001820b68
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002f7f7b0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8002f7f7b0, Wait = 0, Mutex_unk_out = 0xfffffa8002f7f7b0, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002e5ca10, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
RtlInitAnsiStringDestinationString_ptr = 0xfffff880044ca7d0, SourceString_unk = 0xfffff8a001ebfed0
RtlAnsiStringToUnicodeStringDestinationString_ptr = 0xfffff8a001e9a708, SourceString = \Device\NamedPipe\isapi_dg4, AllocateDestinationString = 1, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
IoCreateFileDesiredAccess_unk = 0xc0000000, ObjectAttributes_ptr = 0xfffff880044ca820, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \Device\NamedPipe\isapi_dg4, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x0, ShareAccess = 0x0, Disposition = 0x1, CreateOptions = 0x0, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0xfffff88000000000, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff8a001e9a718, FileHandle_out = 0x0, IoStatusBlock_unk_out = 0xfffff880044ca810, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
RtlNtStatusToDosErrorStatus_unk = 0xc0000034, ret_val_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa8003062510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
KeReleaseMutexMutex_unk = 0xfffffa8003062510, Wait = 0, Mutex_unk_out = 0xfffffa8003062510, ret_val_out = 0
KeWaitForSingleObjectObject_ptr = 0xfffffa8002db2820, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8002db2820, Wait = 0, Mutex_unk_out = 0xfffffa8002db2820, ret_val_out = 0
RtlFreeAnsiStringAnsiString_ptr = 0xfffff8a001e9a6f8
RtlFreeAnsiStringAnsiString = \
KeReleaseMutexMutex_unk = 0xfffffa8002e5ca10, Wait = 0, Mutex_unk_out = 0xfffffa8002e5ca10, ret_val_out = 0
KeDelayExecutionThreadWaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff880044caba0, Interval = -100000000
Execution Path #584 (length: 1613, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length1613
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentThreadret_val_out = 0xfffffa8002e72880
randret_val_out = 14463
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800435e000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002e2ada8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff8800437b000
IofCompleteRequestIrp_unk = 0xfffffa8002e2ad00, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002ff5cd8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e64000
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9c000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007e9d000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ec9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eca000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ece000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ecf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed2000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed3000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed4000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed5000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed6000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed7000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed8000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ed9000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eda000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edb000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edc000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edd000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ede000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007edf000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee0000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f1d0b8
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002bdce50, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee1000
IofCompleteRequestIrp_unk = 0xfffffa8002f1d010, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007ee3000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88007eec000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x3293e00, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x3293000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0xc0000054
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b93000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b97000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x94000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x94000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9b000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9c000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9d000
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9e000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0x92000, RegionSize_ptr = 0xfffff880045bbb58, BaseAddress_ptr_out = 0xfffff880045bbb50, BaseAddress_out = 0x92000, RegionSize_ptr_out = 0xfffff880045bbb58, IoStatus_unk_out = 0xfffff880045bbb00, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000b9f000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8003227378
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88000bb0000
ZwFlushVirtualMemoryProcessHandle_unk = 0xffffffffffffffff, BaseAddress_ptr = 0xfffff880045bbb50, BaseAddress = 0xc88fe00, RegionSize_ptr = 0xfffff880045bbb58
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
IofCompleteRequestIrp_unk = 0xfffffa80032272d0, PriorityBoost = 0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeWaitForSingleObjectObject_ptr = 0xfffffa8001c2cee0, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
ExInterlockedRemoveHeadListListHead_unk = 0xfffffa8001c2cec8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0xfffffa8002f18c78
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa8001ae4000, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffff8a000000010, ret_val_ptr_out = 0xfffff88004800000
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Code Block #13 ( EP #573)
+
InformationValue
TriggerPspSystemThreadStartup+0x57
Start Address0xfffffa8001bdfef4
Execution Path #573 (length: 739, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length739
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018b0040
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = X, _MaxCount = 0x6, ret_val_out = -5
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 91
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = HH , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 101
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = H , _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 112
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -61
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 106
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 107
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = 99
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = Vp, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = p, _MaxCount = 0x6, ret_val_out = 3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -25
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = -27
_strnicmp_Str1 = System, _Str2 = 4 h, _MaxCount = 0x6, ret_val_out = 63
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 103
_strnicmp_Str1 = System, _Str2 = h, _MaxCount = 0x6, ret_val_out = 11
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 109
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -24
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -88
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -110
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -94
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 111
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -69
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -105
_strnicmp_Str1 = System, _Str2 = V, _MaxCount = 0x6, ret_val_out = -3
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -98
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -20
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = /, _MaxCount = 0x6, ret_val_out = 68
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -70
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -18
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 113
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -77
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = -93
_strnicmp_Str1 = System, _Str2 = k, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 90
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = K@, _MaxCount = 0x6, ret_val_out = 8
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 97
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -28
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 114
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -13
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -135
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 102
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = @, _MaxCount = 0x6, ret_val_out = 51
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = -125
_strnicmp_Str1 = System, _Str2 = `, _MaxCount = 0x6, ret_val_out = 19
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -45
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -133
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -139
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = -140
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 108
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -29
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -87
_strnicmp_Str1 = System, _Str2 = w, _MaxCount = 0x6, ret_val_out = -4
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = , _MaxCount = 0x6, ret_val_out = 115
_strnicmp_Str1 = System, _Str2 = System, _MaxCount = 0x6, ret_val_out = 0
PsTerminateSystemThreadExitStatus_unk = 0x0
Kernel Graph 73
No Kernel Graph Available
Code Block #77 ( EP #129, #290, #480, #557, #558, #561, #568)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001c02015
Execution Path #129 (length: 251, amount: 1, processes: 1)
+
InformationValue
Sequence Length251
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Program Files (x86)\Google\Update\GoogleUpdate.exe, _String2 = Windows, _MaxCount = 0x7, ret_val_out = -7
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
ProbeForReadAddress_ptr = 0x49e040, Length_ptr = 0x8, Alignment = 0x1
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x264, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0x0, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff880044dd9e0, ret_val_unk_out = 0x0
ZwQueryInformationProcessProcessHandle_unk = 0xffffffff80000804, ProcessInformationClass_unk = 0x0, ProcessInformationLength = 0x30, ProcessInformation_ptr_out = 0xfffff880044dd9f0, ReturnLength_ptr_out = 0x0, ret_val_unk_out = 0x0
KeGetCurrentIrqlret_val_unk_out = 0x0
PsLookupProcessByProcessIdProcessId_unk = 0x3e8, Process_unk_out = 0xfffff880044dd818, ret_val_unk_out = 0x0
strncpy_Source = GoogleUpdate.e, _Count = 0x104, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
ObfDereferenceObjectObject_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x4
_stricmp_Str1 = GoogleUpdate.e, _Str2 = svchost.exe, ret_val_out = -12
ZwCloseHandle_unk = 0xffffffff80000804, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd750, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76405038, Length_ptr = 0x9c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x270, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x8
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76400e00, Length_ptr = 0x84, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76400e98, Length_ptr = 0xa6, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0x96, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd830, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x270, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x7
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e940, Length_ptr = 0x88, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x76408b64, Length_ptr = 0x2a, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e940, Length_ptr = 0x2e, Alignment = 0x2
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\apphelp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\apphelp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x49e9c0, Length_ptr = 0x46, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\SysWOW64\apphelp.dll, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = SysWOW64\apphelp.dll, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 79
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e5c8, Length_ptr = 0x40, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #290 (length: 61, amount: 1, processes: 1)
+
InformationValue
Sequence Length61
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #480 (length: 127, amount: 1, processes: 1)
+
InformationValue
Sequence Length127
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15c6760, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #557 (length: 21, amount: 1, processes: 1)
+
InformationValue
Sequence Length21
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
Execution Path #558 (length: 14, amount: 1, processes: 1)
+
InformationValue
Sequence Length14
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #561 (length: 70, amount: 1, processes: 1)
+
InformationValue
Sequence Length70
Processes
+
ProcessAmount
Process 15 (svchost.exe, PID: 836)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #568 (length: 561, amount: 1, processes: 1)
+
InformationValue
Sequence Length561
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xca
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f9db60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f9db60, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5b00, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2710, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
Kernel Graph 74
No Kernel Graph Available
Code Block #78 ( EP #133)
+
InformationValue
TriggerExGetPreviousMode+0xf
Start Address0xfffffa8001bcd573
Execution Path #133 (length: 357, amount: 1, processes: 1)
+
InformationValue
Sequence Length357
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
IoAllocateMdlVirtualAddress_ptr = 0x189e598, Length = 0xc, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa8002e516c0
ExGetPreviousModeret_val_unk_out = 0xfffffa80031f6701
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, AccessMode_unk = 0xfffffa8002e51601, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa8002e516c0, MemoryDescriptorList_unk_out = 0xfffffa8002e516c0
IoFreeMdlMdl_unk = 0xfffffa8002e516c0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000804, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880044dd830, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49e118, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x563888, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a00136efa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00136efa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189eb9c, Length_ptr = 0x40, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ProbeForReadAddress_ptr = 0x49ea20, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x189e7fc, Length_ptr = 0x40, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
_wcsnicmp_String1 = Windows\AppPatch\sysmain.sdb, _String2 = Windows, _MaxCount = 0x7, ret_val_out = 0
_wcsnicmp_String1 = AppPatch\sysmain.sdb, _String2 = $NtUninstallQ923283$, _MaxCount = 0x13, ret_val_out = 61
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x29c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001bcd970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bcd970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x298, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003163640, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003163640, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x268, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8001acff20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8001acff20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x26c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a0012b1a50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0012b1a50, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x264, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x6
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x258, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa8003138810, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003138810, ret_val_ptr_out = 0x3
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x25c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001ec26c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ec26c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x24c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001630c50, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001630c50, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x250, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001164340, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001164340, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x254, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffff8a001e1ec70, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e1ec70, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x26c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880044dda80, Object_out = 0xfffffa800251c060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800251c060, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
PsGetCurrentProcessret_val_out = 0xfffffa80031529e0
strncpy_Source = GoogleUpdate.e, _Count = 0x52, _Dest_out = GoogleUpdate.e, ret_val_out = GoogleUpdate.e
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
_strnicmp_Str1 = GoogleUpdate.e, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -14
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Kernel Graph 75
No Kernel Graph Available
Code Block #79 ( EP #164)
+
InformationValue
Trigger_snwprintf+0xd2
Start Address0xfffffa8001bdf40e
Execution Path #164 (length: 132, amount: 1, processes: 1)
+
InformationValue
Sequence Length132
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
wcsncpy_Source = \??\Par1\system, _Count = 0x104, _Dest_out = \??\Par1\system, ret_val_out = \??\Par1\system
RtlInitUnicodeStringSourceString = \??\Par1\system, DestinationString_out = \??\Par1\system
IoCreateFileDesiredAccess_unk = 0x100001, ObjectAttributes_ptr = 0xfffff880022c9918, ObjectAttributes_deref_Length = 0x30, ObjectAttributes_deref_RootDirectory_unk = 0x0, ObjectAttributes_deref_ObjectName = \??\Par1\system, ObjectAttributes_deref_Attributes = 0x40, ObjectAttributes_deref_SecurityDescriptor_ptr = 0x0, ObjectAttributes_deref_SecurityQualityOfService_ptr = 0x0, AllocationSize_ptr = 0x0, FileAttributes = 0x80, ShareAccess = 0x3, Disposition = 0x1, CreateOptions = 0x10, EaBuffer_ptr = 0x0, EaLength = 0x0, CreateFileType_unk = 0x0, InternalParameters_ptr = 0x0, Options = 0x100, FileHandle_ptr_out = 0xfffff880022c98f0, FileHandle_out = 0xfffff8a0003074bf, IoStatusBlock_unk_out = 0xfffff880022c9908, ret_val_unk_out = 0xc0000034
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002ff5cd8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002ff5cd8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
_wcsnicmp_String1 = FltMgr, _String2 = netbt, _MaxCount = 0x6, ret_val_out = -8
_wcsnicmp_String1 = FltMgr, _String2 = afd, _MaxCount = 0x6, ret_val_out = 5
_wcsnicmp_String1 = FltMgr, _String2 = Null, _MaxCount = 0x6, ret_val_out = -8
_wcsnicmp_String1 = FltMgr, _String2 = Beep, _MaxCount = 0x6, ret_val_out = 4
_wcsnicmp_String1 = FltMgr, _String2 = tcpip, _MaxCount = 0x6, ret_val_out = -14
_wcsnicmp_String1 = FltMgr, _String2 = Nsiproxy, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
_wcsnicmp_String1 = fastfat, _String2 = netbt, _MaxCount = 0x7, ret_val_out = -8
_wcsnicmp_String1 = fastfat, _String2 = afd, _MaxCount = 0x7, ret_val_out = 5
_wcsnicmp_String1 = fastfat, _String2 = Null, _MaxCount = 0x7, ret_val_out = -8
_wcsnicmp_String1 = fastfat, _String2 = Beep, _MaxCount = 0x7, ret_val_out = 4
_wcsnicmp_String1 = fastfat, _String2 = tcpip, _MaxCount = 0x7, ret_val_out = -14
_wcsnicmp_String1 = fastfat, _String2 = Nsiproxy, _MaxCount = 0x7, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
IofCompleteRequestIrp_unk = 0xfffffa8002ff5c30, PriorityBoost = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
Kernel Graph 76
No Kernel Graph Available
Code Block #80 ( EP #143)
+
InformationValue
Triggerunknown_0xfffffa8001be0000+0x2
Start Address0xfffff800026de1d0
Execution Path #143 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa8002d8ab30
Kernel Graph 77
No Kernel Graph Available
Code Block #81 ( EP #144)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x830
Start Address0xfffff800026c3220
Execution Path #144 (length: 1, amount: 1, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)1
Sequence
+
SymbolParameters
strncpy_Source = svchost.exe, _Count = 0x52, _Dest_out = svchost.exe, ret_val_out = svchost.exe
Kernel Graph 78
No Kernel Graph Available
Code Block #82 ( EP #145)
+
InformationValue
Triggerunknown_0xfffffa8001c14000+0x812
Start Address0xfffff8000265b458
Execution Path #145 (length: 1, amount: 2, processes: 1)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 11 (svchost.exe, PID: 564)2
Sequence
+
SymbolParameters
_strnicmp_Str1 = svchost.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
Kernel Graph 79
No Kernel Graph Available
Code Block #83 ( EP #154, #235, #273, #366, #401, #522)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bc9748
Execution Path #154 (length: 494, amount: 1, processes: 1)
+
InformationValue
Sequence Length494
Processes
+
ProcessAmount
Process 34 (googleupdate.exe, PID: 2220)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x74a3f0, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x7
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0xfdeb70, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x737b58, Length_ptr = 0x2a, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #235 (length: 110, amount: 1, processes: 1)
+
InformationValue
Sequence Length110
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff93f0, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #273 (length: 117, amount: 1, processes: 1)
+
InformationValue
Sequence Length117
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x104d710, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bc2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #366 (length: 420, amount: 1, processes: 1)
+
InformationValue
Sequence Length420
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a88f0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16960b0, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f543b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f44720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1696630, Length_ptr = 0x9e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaf138, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xcaf548, Length_ptr = 0x96, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #401 (length: 1203, amount: 1, processes: 1)
+
InformationValue
Sequence Length1203
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000badac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000badac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000baeac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000baeac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bafac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bafac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eac0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb1ac0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb1ac0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb2ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb2ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb3ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb3ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb4ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb4ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb5ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb5ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb6ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb6ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb7ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb7ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb8ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb8ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bb9ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bb9ad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbaad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bbaad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbbad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bbbad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbcad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bbcad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbdad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bbdad0, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8eb60, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80027896b0
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80027896b0, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88000bbeb60
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88000bbeb60, MemoryDescriptorList_unk = 0xfffffa80027896b0
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80027896b0, MemoryDescriptorList_unk_out = 0xfffffa80027896b0
IoFreeMdlMdl_unk = 0xfffffa80027896b0
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e3a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e538, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e398, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4d5920, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e888, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e6e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e1e8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8e048, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b2550, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2b0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8e948, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1a8e990, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb4770, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb4770, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x2ac, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002e2af10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e2af10, ret_val_ptr_out = 0x1
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Execution Path #522 (length: 502, amount: 1, processes: 1)
+
InformationValue
Sequence Length502
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x158acf0, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b75a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x158aae0, Length_ptr = 0x9e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x166c2d0, Length_ptr = 0x102, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001bfb5b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001bfb5b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bb140, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Kernel Graph 80
No Kernel Graph Available
Code Block #84 ( EP #581, #165, #203, #205, #306, #377, #445, #452, #473, #552, #595, #562)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001be0667
Execution Path #581 (length: 107, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length107
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff88003fb2340, Object_out = 0xfffffa80030edb30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa80030edb30, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffffa8002e6f9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002e6f9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x8ac
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003fb2a80, Object_out = 0xfffff8a001eeba30, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001eeba30, ret_val_ptr_out = 0x13
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #165 (length: 116, amount: 1, processes: 1)
+
InformationValue
Sequence Length116
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ExInterlockedInsertTailListListHead_unk = 0xfffffa8001c2cec8, ListEntry_unk = 0xfffffa8002f1d0b8, Lock_unk = 0xfffffa8001c2ced8, ListHead_unk_out = 0xfffffa8001c2cec8, ListEntry_unk_out = 0xfffffa8002f1d0b8, Lock_unk_out = 0xfffffa8001c2ced8, ret_val_unk_out = 0x0
KeSetEventEvent_unk = 0xfffffa8001c2cee0, Increment_unk = 0x0, Wait = 0, Event_unk_out = 0xfffffa8001c2cee0, ret_val_out = 0
Execution Path #203 (length: 216, amount: 1, processes: 1)
+
InformationValue
Sequence Length216
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x36e000, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f05010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfa5f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #205 (length: 43, amount: 1, processes: 1)
+
InformationValue
Sequence Length43
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #306 (length: 277, amount: 1, processes: 1)
+
InformationValue
Sequence Length277
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x150fb60, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d9790, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #377 (length: 169, amount: 1, processes: 1)
+
InformationValue
Sequence Length169
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1696790, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #445 (length: 369, amount: 1, processes: 1)
+
InformationValue
Sequence Length369
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x397700, Length_ptr = 0x108, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3e2f00, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef7bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #452 (length: 238, amount: 1, processes: 1)
+
InformationValue
Sequence Length238
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf8bc80, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1049910, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #473 (length: 130, amount: 2, processes: 1)
+
InformationValue
Sequence Length130
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15c8750, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #552 (length: 23, amount: 1, processes: 1)
+
InformationValue
Sequence Length23
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
ProbeForReadAddress_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #595 (length: 28, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length28
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x49c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002ed2f20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ed2f20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8002ecfe00, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002ecfe00, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
Execution Path #562 (length: 433, amount: 1, processes: 1)
+
InformationValue
Sequence Length433
Processes
+
ProcessAmount
Process 15 (svchost.exe, PID: 836)1
Sequence
+
SymbolParameters
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdba8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefadbdc90, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fda08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x2e624a0, Length_ptr = 0x4c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fdfb8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x21fe000, Length_ptr = 0x74, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3e130
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3e130, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f3f130
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f3f130, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f50130
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f50130, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe130, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f51130
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f51130, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f52140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f52140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f53140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f53140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f54140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f54140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f55140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f55140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f56140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f56140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f57140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f57140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f58140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f58140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fe140, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f59140
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f59140, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x21fe238, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
ProbeForReadAddress_ptr = 0x21fe098, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x263ee00, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x344
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
ObfReferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf4
PsGetCurrentProcessret_val_out = 0xfffffa8002edb290
IoAllocateMdlVirtualAddress_ptr = 0x21fdef0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007f5aef0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007f5aef0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002edb290, ret_val_ptr_out = 0xf3
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffffa800322b180, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa800322b180, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x344
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x4dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88004774a80, Object_out = 0xfffff8a00183c8c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183c8c0, ret_val_ptr_out = 0x5
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Kernel Graph 81
No Kernel Graph Available
Code Block #85 ( EP #168)
+
InformationValue
Triggerunknown_0xfffffa8001bdc000+0xa24
Start Address0xfffff800029412b8
Execution Path #168 (length: 1, amount: 8, processes: 2)
+
InformationValue
Sequence Length1
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)2
Process 18 (svchost.exe, PID: 264)6
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4
Kernel Graph 82
No Kernel Graph Available
Code Block #86 ( EP #169)
+
InformationValue
Triggerunknown_0xfffffa8001c02000+0x70
Start Address0xfffff8000299d04c
Execution Path #169 (length: 6, amount: 2, processes: 2)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 1 (55b17467da6d12ecf71e82eb96870bd314f248675da1bfad1b1e437b45453452.exe, PID: 2828)1
Process 39 (googlecrashhandler.exe, PID: 2460)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x18e894, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0xb0c
ProbeForReadAddress_ptr = 0x8e2a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x18e894, Length_ptr = 0x8c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0xb0c
Kernel Graph 83
No Kernel Graph Available
Code Block #87 ( EP #186, #198, #213, #218, #223, #224, #229, #232, #254, #364, #382, #422, #441, #457, #474, #526, #540)
+
InformationValue
TriggerObReferenceObjectByHandle+0x29
Start Address0xfffffa8001bc9b5e
Execution Path #186 (length: 190, amount: 1, processes: 1)
+
InformationValue
Sequence Length190
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35c300, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #198 (length: 254, amount: 1, processes: 1)
+
InformationValue
Sequence Length254
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38bab0, Length_ptr = 0xd2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x38bd50, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a72bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #213 (length: 3, amount: 3, processes: 2)
+
InformationValue
Sequence Length3
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #218 (length: 18, amount: 1, processes: 1)
+
InformationValue
Sequence Length18
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #223 (length: 63, amount: 1, processes: 1)
+
InformationValue
Sequence Length63
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #224 (length: 15, amount: 1, processes: 1)
+
InformationValue
Sequence Length15
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #229 (length: 290, amount: 1, processes: 1)
+
InformationValue
Sequence Length290
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37d650, Length_ptr = 0x14a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800720, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf80210, Length_ptr = 0xf8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #232 (length: 215, amount: 1, processes: 1)
+
InformationValue
Sequence Length215
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc2bb0, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfdf820, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f007d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #254 (length: 66, amount: 1, processes: 1)
+
InformationValue
Sequence Length66
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #364 (length: 112, amount: 1, processes: 1)
+
InformationValue
Sequence Length112
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #382 (length: 30, amount: 1, processes: 1)
+
InformationValue
Sequence Length30
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #422 (length: 127, amount: 1, processes: 1)
+
InformationValue
Sequence Length127
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1652e80, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce9bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce9bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #441 (length: 282, amount: 1, processes: 1)
+
InformationValue
Sequence Length282
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xff6cc0, Length_ptr = 0x92, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160af80, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #457 (length: 225, amount: 1, processes: 1)
+
InformationValue
Sequence Length225
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfae520, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f027d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f7030, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #474 (length: 278, amount: 1, processes: 1)
+
InformationValue
Sequence Length278
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf95880, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47230, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f7a30, Length_ptr = 0xec, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00184dbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #526 (length: 463, amount: 1, processes: 1)
+
InformationValue
Sequence Length463
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32f3d0, Length_ptr = 0x76, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15cd2c0, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001efa970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001efa970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ee94e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ee94e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00183e5e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00183e5e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15ccc00, Length_ptr = 0x7c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000630, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000630, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000630, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a43260, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a43260, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017e9c80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017e9c80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bb5a0, Length_ptr = 0xd6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000630, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #540 (length: 178, amount: 1, processes: 1)
+
InformationValue
Sequence Length178
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14c4b10, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f21bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e483c0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e483c0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ba2750, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ba2750, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 84
No Kernel Graph Available
Code Block #88 ( EP #188, #197, #243, #338, #387, #465, #472)
+
InformationValue
TriggerKiInterruptDispatch+0x34b
Start Address0xfffffa8001bc9793
Execution Path #188 (length: 152, amount: 1, processes: 1)
+
InformationValue
Sequence Length152
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x35c680, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #197 (length: 26, amount: 1, processes: 1)
+
InformationValue
Sequence Length26
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
Execution Path #243 (length: 33, amount: 1, processes: 1)
+
InformationValue
Sequence Length33
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #338 (length: 138, amount: 1, processes: 1)
+
InformationValue
Sequence Length138
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x160c140, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #387 (length: 257, amount: 1, processes: 1)
+
InformationValue
Sequence Length257
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33ccb0, Length_ptr = 0xca, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e52bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x33ce70, Length_ptr = 0xce, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #465 (length: 163, amount: 1, processes: 1)
+
InformationValue
Sequence Length163
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15742e0, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #472 (length: 380, amount: 1, processes: 1)
+
InformationValue
Sequence Length380
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1581b70, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4640, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15c8000, Length_ptr = 0xc2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed0180, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15c8410, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Kernel Graph 85
No Kernel Graph Available
Code Block #89 ( EP #195, #242, #327, #396, #505)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bcc813
Execution Path #195 (length: 99, amount: 1, processes: 1)
+
InformationValue
Sequence Length99
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30ee50, Length_ptr = 0xda, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001cd8201, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #242 (length: 51, amount: 1, processes: 1)
+
InformationValue
Sequence Length51
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
Execution Path #327 (length: 230, amount: 1, processes: 1)
+
InformationValue
Sequence Length230
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1560e40, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f18bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #396 (length: 229, amount: 1, processes: 1)
+
InformationValue
Sequence Length229
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3a3f00, Length_ptr = 0xa6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #505 (length: 38, amount: 1, processes: 1)
+
InformationValue
Sequence Length38
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 86
No Kernel Graph Available
Code Block #90 ( EP #202, #316, #323, #381, #408)
+
InformationValue
TriggerObfDereferenceObject+0x57
Start Address0xfffffa8001bc9ba9
Execution Path #202 (length: 158, amount: 1, processes: 1)
+
InformationValue
Sequence Length158
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x37b880, Length_ptr = 0xfc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa6010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x36de00, Length_ptr = 0xea, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #316 (length: 189, amount: 1, processes: 1)
+
InformationValue
Sequence Length189
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1543de0, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a95bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #323 (length: 273, amount: 1, processes: 1)
+
InformationValue
Sequence Length273
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x157c240, Length_ptr = 0xb8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f16670, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1575320, Length_ptr = 0xb2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #381 (length: 171, amount: 1, processes: 1)
+
InformationValue
Sequence Length171
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1687df0, Length_ptr = 0x7a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a795e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16884b0, Length_ptr = 0x7c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec2010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cda7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Execution Path #408 (length: 277, amount: 1, processes: 1)
+
InformationValue
Sequence Length277
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf67780, Length_ptr = 0x152, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x154b000, Length_ptr = 0x13c, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 87
No Kernel Graph Available
Code Block #91 ( EP #207, #247, #251, #257, #267, #286, #390, #501, #566)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bcc465
Execution Path #207 (length: 34, amount: 2, processes: 1)
+
InformationValue
Sequence Length34
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #247 (length: 125, amount: 1, processes: 1)
+
InformationValue
Sequence Length125
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f127d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfc38d0, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #251 (length: 86, amount: 1, processes: 1)
+
InformationValue
Sequence Length86
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #257 (length: 130, amount: 1, processes: 1)
+
InformationValue
Sequence Length130
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #267 (length: 145, amount: 1, processes: 1)
+
InformationValue
Sequence Length145
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1046a40, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001b9baa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f547d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #286 (length: 128, amount: 1, processes: 1)
+
InformationValue
Sequence Length128
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14aa4e0, Length_ptr = 0xd6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014c27e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efc4f0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #390 (length: 122, amount: 1, processes: 1)
+
InformationValue
Sequence Length122
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183cbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e48010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #501 (length: 168, amount: 1, processes: 1)
+
InformationValue
Sequence Length168
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1616270, Length_ptr = 0xfc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #566 (length: 122, amount: 1, processes: 1)
+
InformationValue
Sequence Length122
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3812a0, Length_ptr = 0xfe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800006dc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001638bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800006dc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800006dc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800006dc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800006dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 88
No Kernel Graph Available
Code Block #92 ( EP #215, #250, #295, #304, #318, #369, #432, #436, #438, #461, #493, #554)
+
InformationValue
Trigger__ascii_strnicmp+0x43
Start Address0xfffffa8001bcc633
Execution Path #215 (length: 75, amount: 1, processes: 1)
+
InformationValue
Sequence Length75
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e7d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #250 (length: 81, amount: 1, processes: 1)
+
InformationValue
Sequence Length81
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a4aae0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #295 (length: 158, amount: 1, processes: 1)
+
InformationValue
Sequence Length158
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d8c50, Length_ptr = 0xde, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
Execution Path #304 (length: 189, amount: 1, processes: 1)
+
InformationValue
Sequence Length189
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x150f560, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
Execution Path #318 (length: 47, amount: 1, processes: 1)
+
InformationValue
Sequence Length47
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #369 (length: 125, amount: 1, processes: 1)
+
InformationValue
Sequence Length125
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehexthost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x10, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiActivScp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiBmlDataCarousel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiExtens, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiiTV, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x14, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiProxy, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x15, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiTVMSMusic, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x16, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUPnP, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x17, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiUserXp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x18, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiVidCtl, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x19, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiwmp, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehiWUapi, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = ehRecObj, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 16
Execution Path #432 (length: 94, amount: 1, processes: 1)
+
InformationValue
Sequence Length94
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #436 (length: 103, amount: 1, processes: 1)
+
InformationValue
Sequence Length103
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #438 (length: 116, amount: 1, processes: 1)
+
InformationValue
Sequence Length116
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f6030, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
Execution Path #461 (length: 132, amount: 2, processes: 1)
+
InformationValue
Sequence Length132
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfb08e0, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #493 (length: 67, amount: 1, processes: 1)
+
InformationValue
Sequence Length67
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #554 (length: 23, amount: 1, processes: 1)
+
InformationValue
Sequence Length23
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 89
No Kernel Graph Available
Code Block #93 ( EP #220, #301, #305, #380, #407, #449, #491, #531)
+
InformationValue
TriggerPsGetCurrentProcess+0xd
Start Address0xfffffa8001be0008
Execution Path #220 (length: 25, amount: 1, processes: 1)
+
InformationValue
Sequence Length25
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #301 (length: 228, amount: 1, processes: 1)
+
InformationValue
Sequence Length228
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd87d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144d920, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bfb010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #305 (length: 125, amount: 1, processes: 1)
+
InformationValue
Sequence Length125
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d95b0, Length_ptr = 0xe0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182b010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #380 (length: 208, amount: 1, processes: 1)
+
InformationValue
Sequence Length208
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32f150, Length_ptr = 0x76, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efabf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
Execution Path #407 (length: 280, amount: 1, processes: 1)
+
InformationValue
Sequence Length280
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x3570d0, Length_ptr = 0xf8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014d5720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001eccbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e54060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e54060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x384310, Length_ptr = 0x130, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0017fc060, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0017fc060, ret_val_ptr_out = 0x1
Execution Path #449 (length: 362, amount: 1, processes: 1)
+
InformationValue
Sequence Length362
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1555e60, Length_ptr = 0xf8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x161ebf0, Length_ptr = 0xc0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0019cf600, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #491 (length: 60, amount: 1, processes: 1)
+
InformationValue
Sequence Length60
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #531 (length: 255, amount: 1, processes: 1)
+
InformationValue
Sequence Length255
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bcaa0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a11010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00169a3b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f05a10, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f05a10, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822d60, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822d60, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x148, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00169f970, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00169f970, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x16bcc60, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x134, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed8010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Kernel Graph 90
No Kernel Graph Available
Code Block #94 ( EP #222, #272, #298, #358, #392, #439, #447, #504)
+
InformationValue
TriggerKeReleaseMutant+0x17c
Start Address0xfffffa8001bc96fa
Execution Path #222 (length: 35, amount: 1, processes: 1)
+
InformationValue
Sequence Length35
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #272 (length: 313, amount: 1, processes: 1)
+
InformationValue
Sequence Length313
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x144ca20, Length_ptr = 0xf6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f46010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1466b80, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a29bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
Execution Path #298 (length: 75, amount: 1, processes: 1)
+
InformationValue
Sequence Length75
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d9010, Length_ptr = 0xe6, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001630010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
Execution Path #358 (length: 164, amount: 1, processes: 1)
+
InformationValue
Sequence Length164
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1625250, Length_ptr = 0xc4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f47650, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #392 (length: 118, amount: 1, processes: 1)
+
InformationValue
Sequence Length118
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x334cc0, Length_ptr = 0xdc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0a650, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #439 (length: 352, amount: 1, processes: 1)
+
InformationValue
Sequence Length352
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1503f10, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a000304010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1606460, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a8bb01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x165a0e0, Length_ptr = 0xd0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001efa010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #447 (length: 213, amount: 1, processes: 1)
+
InformationValue
Sequence Length213
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x161e230, Length_ptr = 0xbe, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ef8bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0019dfad0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0019dfad0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00020b410, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00020b410, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #504 (length: 134, amount: 1, processes: 1)
+
InformationValue
Sequence Length134
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1441f50, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12640, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00030a6a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00030a6a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 91
No Kernel Graph Available
Code Block #95 ( EP #239)
+
InformationValue
TriggerKiSystemServiceExit+0x1a6
Start Address0xfffffa8001bc9ccf
Execution Path #239 (length: 39, amount: 2, processes: 1)
+
InformationValue
Sequence Length39
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)2
Sequence
+
SymbolParameters
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 92
No Kernel Graph Available
Code Block #96 ( EP #261, #361, #371, #376, #389, #453, #520)
+
InformationValue
TriggerKiSystemServiceExit+0x1a6
Start Address0xfffffa8001bca13d
Execution Path #261 (length: 80, amount: 1, processes: 1)
+
InformationValue
Sequence Length80
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #361 (length: 276, amount: 1, processes: 1)
+
InformationValue
Sequence Length276
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f0abf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x15a8490, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f52010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bcebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #371 (length: 521, amount: 1, processes: 1)
+
InformationValue
Sequence Length521
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = Microsoft.MediaCenter.TV.Tuners.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x47, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.MediaCenter.UI, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x48, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Diagnostics, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x49, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Commands.Utility, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.ConsoleHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Editor, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GPowerShell, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.GraphicalHost, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x4f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.PowerShell.Security, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x50, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.Cmdlets, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x51, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyEngineApi.Interop, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x52, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyManager, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x53, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.PolicyModel, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x54, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.PolicyManagement.XmlHelper, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x55, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Security.ApplicationId.Wizards.AutomaticRuleGenerationWizard, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x56, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x57, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x58, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x59, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Transactions.Bridge.Dtc, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Activities.Compiler, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualBasic.Compatibility.Data, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x5f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualC, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x60, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.VisualC, Version=8.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x61, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.Commands.GetDiagInput, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x62, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x63, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x64, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x65, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.SDEngine, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x66, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.SDHost, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x67, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Windows.Diagnosis.TroubleshootingPack, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x68, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.Workflow.Compiler, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x69, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.WSMan.Management, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Microsoft.WSMan.Runtime, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MiguiControls, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MMCEx, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MMCFxCommon, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = MSBuild, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x6f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mscorlib, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x70, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 24
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x71, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napcrypt, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x72, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = naphlpr, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x73, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napinit, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x74, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = napsnap, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 25
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x75, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = Narrator, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -7
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x76, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationBuildTasks, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x77, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationBuildTasks, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x78, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCFFRasterizer, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x79, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCore, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x7a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -5
Execution Path #376 (length: 576, amount: 1, processes: 1)
+
InformationValue
Sequence Length576
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = System.Web.Extensions.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x113, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Extensions.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x114, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Mobile, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x115, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Mobile, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x116, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.RegularExpressions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x117, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.RegularExpressions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x118, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Routing, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x119, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Services, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Controls.Ribbon, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Forms, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x11f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Forms.DataVisualization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x120, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Forms.DataVisualization.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x121, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Input.Manipulations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x122, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Presentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x123, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Windows.Presentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x124, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.Activities, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x125, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x126, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.ComponentModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x127, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.ComponentModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x128, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.Runtime, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x129, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Workflow.Runtime, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.WorkflowServices, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.WorkflowServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xaml.Hosting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x12f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x130, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xml.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x131, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xml.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x132, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Xml.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x133, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = TaskScheduler, Version=6.1.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -1
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x134, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationClient, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x135, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x136, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationClientsideProviders, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x137, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationClientsideProviders, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x138, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationProvider, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x139, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationProvider, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13a, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationTypes, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13b, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = UIAutomationTypes, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13c, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WindowsBase, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13d, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13e, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WindowsFormsIntegration, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x13f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WindowsFormsIntegration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x140, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = WsatConfig, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x141, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = XamlBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x142, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = XsdBuildTask, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = 3
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x100, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30f120, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #389 (length: 44, amount: 1, processes: 1)
+
InformationValue
Sequence Length44
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #453 (length: 204, amount: 1, processes: 1)
+
InformationValue
Sequence Length204
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfa22c0, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0014b6690, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #520 (length: 1601, amount: 1, processes: 1)
+
InformationValue
Sequence Length1601
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
wcsncmp_String1 = System.AddIn.Contract, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x9f, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.Composition, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.Composition.Registration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.DataAnnotations, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ComponentModel.DataAnnotations, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration.Install, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Configuration.Install, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Core, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xa9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xaa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xab, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.DataSetExtensions, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xac, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.DataSetExtensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xad, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xae, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xaf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Entity.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Linq, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Linq, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.OracleClient, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.OracleClient, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Client, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Client, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xb9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Design, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xba, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.Services.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xbb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.SqlXml, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xbc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Data.SqlXml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xbd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Deployment, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xbe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Deployment, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xbf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Device, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.AccountManagement, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.AccountManagement, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.DirectoryServices.Protocols, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xc9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xca, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing.Design, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xcb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Drawing.Design, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xcc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Dynamic, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xcd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.EnterpriseServices, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xce, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xcf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Selectors, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Selectors, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Compression, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Compression.FileSystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Log, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Log, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xd9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Automation, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xda, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Instrumentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xdb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Instrumentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xdc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Messaging, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xdd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Messaging, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xde, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xdf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net.Http.WebRequest, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Numerics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Printing, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Printing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Reflection.Context, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Caching, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.DurableInstancing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Remoting, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xe9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Remoting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xea, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xeb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xec, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization.Formatters.Soap, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xed, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Runtime.Serialization.Formatters.Soap, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xee, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Security, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xef, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Security, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Activation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Activities, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Channels, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Discovery, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Internals, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Routing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.ServiceMoniker40, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xf9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Web, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xfa, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceModel.Web, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xfb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceProcess, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xfc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.ServiceProcess, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xfd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Speech, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xfe, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Speech, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0xff, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Transactions, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x100, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Transactions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x101, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Web, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x102, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
For performance reasons the remaining entries are omitted.
Click to download all entries as text file.
Kernel Graph 93
No Kernel Graph Available
Code Block #97 ( EP #265, #484)
+
InformationValue
TriggerKiInterruptDispatch+0x34b
Start Address0xfffffa8001bc9993
Execution Path #265 (length: 42, amount: 1, processes: 1)
+
InformationValue
Sequence Length42
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #484 (length: 156, amount: 1, processes: 1)
+
InformationValue
Sequence Length156
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14f8430, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd2bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Kernel Graph 94
No Kernel Graph Available
Code Block #98 ( EP #276)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bc99de
Execution Path #276 (length: 229, amount: 1, processes: 1)
+
InformationValue
Sequence Length229
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1477010, Length_ptr = 0xa2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce43b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 95
No Kernel Graph Available
Code Block #99 ( EP #292, #339, #374, #384, #485)
+
InformationValue
Trigger__ascii_strnicmp+0x43
Start Address0xfffffa8001bcc64d
Execution Path #292 (length: 273, amount: 1, processes: 1)
+
InformationValue
Sequence Length273
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d87a0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00135c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00182e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14dbb70, Length_ptr = 0xaa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a79010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 2, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -35
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ec8010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 3, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -34
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #339 (length: 131, amount: 1, processes: 1)
+
InformationValue
Sequence Length131
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1612200, Length_ptr = 0xa8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aa9bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001ed7a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001ed7a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #374 (length: 234, amount: 1, processes: 1)
+
InformationValue
Sequence Length234
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.EnterpriseServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xcf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Selectors, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Selectors, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IdentityModel.Services, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Compression, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Compression.FileSystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd6, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Log, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd7, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.IO.Log, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd8, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xd9, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Automation, Version=1.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xda, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Instrumentation, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xdb, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Management.Instrumentation, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xdc, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Messaging, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xdd, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Messaging, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xde, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net, Version=3.5.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xdf, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net.Http, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Net.Http.WebRequest, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe2, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Numerics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe3, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Printing, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=amd64, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe4, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Printing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0xe5, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a2e010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = System.Reflection.Context, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -2
Execution Path #384 (length: 214, amount: 1, processes: 1)
+
InformationValue
Sequence Length214
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ecdbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x30e9a0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183c010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f12bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #485 (length: 27, amount: 1, processes: 1)
+
InformationValue
Sequence Length27
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 96
No Kernel Graph Available
Code Block #100 ( EP #303, #353, #451, #478)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bdca2a
Execution Path #303 (length: 153, amount: 1, processes: 1)
+
InformationValue
Sequence Length153
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x1512410, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001aad7e0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd83b0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14d93d0, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f0c460, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c460, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e9f720, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f40010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
Execution Path #353 (length: 162, amount: 1, processes: 1)
+
InformationValue
Sequence Length162
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x162f3a0, Length_ptr = 0x9a, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a119a0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a0d010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001822b90, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001822b90, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #451 (length: 365, amount: 1, processes: 1)
+
InformationValue
Sequence Length365
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x14f6c30, Length_ptr = 0xf4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f13bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1620230, Length_ptr = 0xbc, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ab8aa0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f02010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001a6b401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x1049730, Length_ptr = 0xe2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001e55bf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ce0450, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a00182e630, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e630, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
Execution Path #478 (length: 45, amount: 1, processes: 1)
+
InformationValue
Sequence Length45
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 97
No Kernel Graph Available
Code Block #101 ( EP #315, #470)
+
InformationValue
TriggerPsGetCurrentProcessId+0x10
Start Address0xfffffa8001bc9696
Execution Path #315 (length: 215, amount: 1, processes: 1)
+
InformationValue
Sequence Length215
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x14da4b0, Length_ptr = 0xd8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a6dbf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001844bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001638b80, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001638b80, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x155c020, Length_ptr = 0xa0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff800007fc, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cd47d0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff800007fc, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f237d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff800007fc, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800007fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001b83a20, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001b83a20, ret_val_ptr_out = 0x1
Execution Path #470 (length: 161, amount: 1, processes: 1)
+
InformationValue
Sequence Length161
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xfa6d60, Length_ptr = 0xa4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001820010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001bce1d0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 98
No Kernel Graph Available
Code Block #102 ( EP #395, #479, #535)
+
InformationValue
TriggerKiInterruptDispatchNoLock+0x335
Start Address0xfffffa8001bca065
Execution Path #395 (length: 516, amount: 1, processes: 1)
+
InformationValue
Sequence Length516
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a00183f340, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x368930, Length_ptr = 0xe8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001cdebf0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a7ebf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x368b30, Length_ptr = 0xf2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f4e010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ee9010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x368d30, Length_ptr = 0xf0, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f25010, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001a8bbf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000820, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000820, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f0c3a0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0c3a0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x34c840, Length_ptr = 0xfa, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a0013ca150, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a0013ca150, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000820, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f32a50, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000820, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001ed4bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Execution Path #479 (length: 192, amount: 1, processes: 1)
+
InformationValue
Sequence Length192
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a0017c1bf0, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0xf95b20, Length_ptr = 0xd4, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwDuplicateObjectSourceProcessHandle_unk = 0xffffffffffffffff, SourceHandle_unk = 0x144, TargetProcessHandle_unk = 0xffffffffffffffff, DesiredAccess_unk = 0xfffff88000000000, HandleAttributes = 0x200, Options = 0x2, TargetHandle_ptr_out = 0xfffff8800446c958, ret_val_unk_out = 0x0
ZwQueryKeyKeyHandle_unk = 0xffffffff80000698, KeyInformationClass_unk = 0x2, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001f1e3b0, ResultLength_ptr_out = 0xfffff8800446c9d8, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001800010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Execution Path #535 (length: 71, amount: 1, processes: 1)
+
InformationValue
Sequence Length71
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x0, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 0, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -37
ZwEnumerateKeyKeyHandle_unk = 0xffffffff80000698, Index = 0x1, KeyInformationClass_unk = 0x0, Length = 0x400, KeyInformation_ptr_out = 0xfffff8a001822010, ResultLength_ptr_out = 0xfffffa8001c2c444, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
wcsncmp_String1 = 1, _String2 = Ultra3, _MaxCount = 0x6, ret_val_out = -36
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x401, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a00182e570, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a00182e570, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaed28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32b860, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
Kernel Graph 99
No Kernel Graph Available
Code Block #103 ( EP #482)
+
InformationValue
Triggerwcsncmp+0x2f
Start Address0xfffffa8001bc9da9
Execution Path #482 (length: 79, amount: 1, processes: 1)
+
InformationValue
Sequence Length79
Processes
+
ProcessAmount
Process 33 (mscorsvw.exe, PID: 2028)1
Sequence
+
SymbolParameters
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c600, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ZwCloseHandle_unk = 0xffffffff80000698, ret_val_unk_out = 0x0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000698, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff8800446c6f0, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x2
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xfffff8a001ef7b01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
ProbeForReadAddress_ptr = 0xcaec58, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x32c640, Length_ptr = 0x2, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x14c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001e9b9b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e9b9b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x150, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a000f47930, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a000f47930, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x144, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff8800446ca80, Object_out = 0xfffff8a001f03fa0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f03fa0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x7ec
PsGetCurrentProcessret_val_out = 0xfffffa80018fab30
strncpy_Source = mscorsvw.exe, _Count = 0x52, _Dest_out = mscorsvw.exe, ret_val_out = mscorsvw.exe
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
_strnicmp_Str1 = mscorsvw.exe, _Str2 = Ultra3, _MaxCount = 0x6, ret_val_out = -8
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2cb00
ObReferenceObjectByHandleHandle_unk = 0x134, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0xffffff01, Object_ptr_out = 0xfffff8800446c950, Object_out = 0xfffff8a001baaa40, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001baaa40, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Kernel Graph 100
No Kernel Graph Available
Code Block #104 ( EP #542)
+
InformationValue
TriggerKeLowerIrql+0x7
Start Address0xfffffa8001be06bb
Execution Path #542 (length: 9, amount: 1, processes: 1)
+
InformationValue
Sequence Length9
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
Kernel Graph 101
No Kernel Graph Available
Code Block #105 ( EP #606)
+
InformationValue
Triggerunknown_0xfffffa8001c02000+0x70
Start Address0xfffff88002d558a5
Execution Path #606 (length: 798, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length798
Processes
+
ProcessAmount
Process 2 (System, PID: 4)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000045c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000454, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000044c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000444, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000043c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000434, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000042c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000424, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000041c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000414, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000040c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000404, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003f8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003f0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003d8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000734, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000730, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000073c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000744, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000074c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000754, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000075c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000764, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff8000076c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000660, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800006e8, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000758, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000770, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000774, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000760, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000768, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000750, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000748, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000740, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000738, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000724, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003dc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003d4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003ec, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003f4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff800003fc, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000408, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000410, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000418, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000420, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000428, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x4
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xffffffff80000430, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x0, Object_ptr_out = 0xfffff880047890a0, Object_out = 0xfffffa8002fb73b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002fb73b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x9cc
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x9cc
Kernel Graph 102
No Kernel Graph Available
Code Block #106 ( EP #551)
+
InformationValue
TriggerPsGetCurrentProcess+0xd
Start Address0xfffffa8001bee7c5
Execution Path #551 (length: 177, amount: 1, processes: 1)
+
InformationValue
Sequence Length177
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
IoAllocateMdlVirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007efe180
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007efe180, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
ObfReferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbe
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x132f180, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0e70
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0e70, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007eff180
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007eff180, MemoryDescriptorList_unk = 0xfffffa80025d0e70
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0e70, MemoryDescriptorList_unk_out = 0xfffffa80025d0e70
IoFreeMdlMdl_unk = 0xfffffa80025d0e70
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xbd
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f278, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132f0d8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x4b0100, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f0a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ef08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f280, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f0a8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x132ef08, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x132f280, Length_ptr = 0xc8, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xe0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x624, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffffa8003188320, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8003188320, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e0, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001e48300, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001e48300, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0xd4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff880025daa80, Object_out = 0xfffff8a001f0a3b0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001f0a3b0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x132f358, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x0
Kernel Graph 103
No Kernel Graph Available
Code Block #107 ( EP #556, #559)
+
InformationValue
Triggerunknown_0xfffffa8001c02000+0x70
Start Address0xfffff800029ebb37
Execution Path #556 (length: 4, amount: 1, processes: 1)
+
InformationValue
Sequence Length4
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
ProbeForReadAddress_ptr = 0x132e548, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x7fefcef4710, Length_ptr = 0x28, Alignment = 0x2
Execution Path #559 (length: 6, amount: 1, processes: 1)
+
InformationValue
Sequence Length6
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
KeGetCurrentIrqlret_val_unk_out = 0x0
KeRaiseIrqlToDpcLevelret_val_unk_out = 0x0
KeLowerIrqlNewIrql_unk = 0xfffffa8001c2bc00
KeGetCurrentIrqlret_val_unk_out = 0x2
PsGetCurrentThreadIdret_val_unk_out = 0x15c
KeGetCurrentIrqlret_val_unk_out = 0x0
Kernel Graph 104
No Kernel Graph Available
Code Block #108 ( EP #591)
+
InformationValue
Triggerunknown_0xfffffa80031f3000+0x1a3
Start Address0xfffff800026d6184
Execution Path #591 (length: 35, amount: 1, processes: 1 incomplete)
+
InformationValue
Sequence Length35
Processes
+
ProcessAmount
Process 18 (svchost.exe, PID: 264)1
Sequence
+
SymbolParameters
PsGetCurrentProcessret_val_out = 0xfffffa8002f30350
IoAllocateMdlVirtualAddress_ptr = 0x1a8ead0, Length = 0x70, SecondaryBuffer = 0, ChargeQuota = 0, Irp_unk = 0x0, Irp_unk_out = 0x0, ret_val_unk_out = 0xfffffa80025d0f40
MmProbeAndLockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, Operation_unk = 0x2, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
MmMapLockedPagesSpecifyCacheMemoryDescriptorList_unk = 0xfffffa80025d0f40, AccessMode_unk = 0x0, CacheType_unk = 0x1, BaseAddress_ptr = 0x0, BugCheckOnFailure = 0x0, Priority_unk = 0xfffffa8000000010, ret_val_ptr_out = 0xfffff88007fd3ad0
MmUnmapLockedPagesBaseAddress_ptr = 0xfffff88007fd3ad0, MemoryDescriptorList_unk = 0xfffffa80025d0f40
MmUnlockPagesMemoryDescriptorList_unk = 0xfffffa80025d0f40, MemoryDescriptorList_unk_out = 0xfffffa80025d0f40
IoFreeMdlMdl_unk = 0xfffffa80025d0f40
ObfDereferenceObjectObject_ptr = 0xfffffa8002f30350, ret_val_ptr_out = 0xc9
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffffa8002eb0400, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffffa8002eb0400, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
ProbeForReadAddress_ptr = 0x1a8ebc8, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x778ce8d0, Length_ptr = 0x22, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
ProbeForReadAddress_ptr = 0x1a8ea28, Length_ptr = 0x30, Alignment = 0x4
ProbeForReadAddress_ptr = 0x48d4b0, Length_ptr = 0x5e, Alignment = 0x2
PsGetCurrentProcessIdret_val_unk_out = 0x108
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x1e4, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a261e0, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a261e0, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
PsGetCurrentProcessIdret_val_unk_out = 0x108
KeWaitForSingleObjectObject_ptr = 0xfffffa8003133510, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa8003133510, Wait = 0, Mutex_unk_out = 0xfffffa8003133510, ret_val_out = 0
ObReferenceObjectByHandleHandle_unk = 0x22c, DesiredAccess_unk = 0x0, ObjectType_unk = 0x0, AccessMode_unk = 0x1, Object_ptr_out = 0xfffff88003d64a80, Object_out = 0xfffff8a001a21800, HandleInformation_unk_out = 0x0, ret_val_unk_out = 0x0
ObfDereferenceObjectObject_ptr = 0xfffff8a001a21800, ret_val_ptr_out = 0x1
KeWaitForSingleObjectObject_ptr = 0xfffffa800303a160, WaitReason_unk = 0x0, WaitMode_unk = 0x0, Alertable = 0, Timeout_ptr = 0x0, ret_val_unk_out = 0x0
KeReleaseMutexMutex_unk = 0xfffffa800303a160, Wait = 0, Mutex_unk_out = 0xfffffa800303a160, ret_val_out = 0
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image